← Back to browse · API

CVE-2025-30676

Severity
MEDIUM
CVSS
6.1
EPSS
0.65347
Risk score
47.27
CISA KEV
No
PoC
No
Published
2025-04-01
Modified
2025-04-02
First seen
2026-08-07
Aliases
EUVD-2025-9281, GHSA-VHG6-M6C8-39C2
Products
Apache Software Foundation:Apache OFBiz 0 <18.12.19
Sources
euvd EUVD-2025-9281

Description

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.

References