CVE-2025-30676
moderateCross-Site Scripting (XSS) in Apache OFBiz before 18.12.19
CVE-2025-30676 is a cross-site scripting flaw (CWE-80, 'basic XSS') in Apache OFBiz caused by improper neutralization of script-related HTML tags in a web page. Per the CVSS vector (AV:N/AC:L/PR:N/UI:R/S:C), an unauthenticated attacker requires user interaction — typically getting a user to view attacker-influenced content such as a crafted link or page rendered by the OFBiz web interface. If triggered, the attacker's script executes in the victim's browser within the OFBiz origin (scope change), yielding limited confidentiality and integrity impact and no availability impact. All Apache OFBiz releases before 18.12.19 are affected, and users are advised to upgrade to 18.12.19, which fixes the issue. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, but the 67.6% EPSS score (99th percentile) indicates an elevated predicted likelihood of exploitation within 30 days.
What to do: Upgrade to Apache OFBiz 18.12.19 or later, as this release fixes the issue. Until patched, restrict access to the OFBiz web interface (e.g., limit exposure to trusted networks) and review access logs for suspicious crafted URLs or unexpected HTML/script content. Given the high EPSS score, monitor for emerging proofs-of-concept and advisories.
| Apache OFBiz | before 18.12.19 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.19. Users are recommended to upgrade to version 18.12.19, which fixes the issue.
- Vendors
- apache
- Products
- ofbiz
- Weakness
- CWE-80, CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.