Medium severity6.1NVD Advisory· Published Apr 1, 2025· Updated Jun 17, 2026
CVE-2025-30676
CVE-2025-30676
Description
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 18.12.19.
Users are recommended to upgrade to version 18.12.19, which fixes the issue.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
5- issues.apache.org/jira/browse/OFBIZ-13219nvdIssue TrackingPatch
- ofbiz.apache.org/security.htmlnvdPatchVendor Advisory
- www.openwall.com/lists/oss-security/2025/04/01/5nvdMailing List
- lists.apache.org/thread/8d718qt8dqthnw1gmyxsq8glfdjklnjfnvdMailing List
- ofbiz.apache.org/download.htmlnvdProduct
News mentions
0No linked articles in our index yet.