Home

Description

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

PUBLISHED Reserved 2026-03-09 | Published 2026-05-19 | Updated 2026-05-19 | Assigner apache

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-94 Improper Control of Generation of Code ('Code Injection')

Product status

Default status
unaffected

Any version before 24.09.06
affected

Credits

Sho Odagiri of GMO Cybersecurity by Ierae, Inc. reporter

Emily Bishop of 992labs reporter

References

www.openwall.com/lists/oss-security/2026/05/19/18

lists.apache.org/thread/1tcnkxjm0s6n1ohfb21brl25dt0hv9by vendor-advisory

cve.org (CVE-2026-31379)

nvd.nist.gov (CVE-2026-31379)

Download JSON