Cross-Site Scripting Vulnerability in Apache OFBiz
CVE-2026-31906

6.1MEDIUM

Key Information:

Vendor

Apache

Vendor
CVE Published:
19 May 2026

What is CVE-2026-31906?

A Cross-Site Scripting (XSS) vulnerability exists in Apache OFBiz due to improper neutralization of user input during web page generation. This flaw may allow attackers to inject malicious scripts into web pages viewed by other users, potentially compromising sensitive user data and leading to further exploitation of the application. It is essential for users to update to version 24.09.06 to mitigate this risk and secure their web applications against possible attacks.

Affected Version(s)

Apache OFBiz 0 < 24.09.06

References

CVSS V3.1

Score:
6.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sho Odagiri of GMO Cybersecurity by Ierae, Inc.
.