A vulnerability marked as critical has been reported in Apache OFBiz up to 24.09.05. This issue affects some unknown processing. Performing a manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-29220. It is possible to initiate the attack remotely. There is no exploit available.
It is suggested to upgrade the affected component.
A vulnerability described as problematic has been identified in Apache OFBiz up to 24.09.05. Impacted is an unknown function. Executing a manipulation can lead to improper input validation.
This vulnerability is registered as CVE-2026-31378. The attack requires access to the local network. No exploit is available.
Upgrading the affected component is recommended.
A vulnerability classified as critical has been found in Apache OFBiz up to 24.09.05. The affected element is an unknown function of the component Expression Language Statement Handler. The manipulation leads to improper neutralization of special elements used in an expression language statement.
This vulnerability is documented as CVE-2026-31380. The attack can be initiated remotely. There is not any exploit available.
It is recommended to upgrade the affected component.
A vulnerability classified as critical was found in Apache OFBiz up to 24.09.05. The impacted element is an unknown function. The manipulation results in improper access controls.
This vulnerability is reported as CVE-2026-31388. The attacker must have access to the local network to execute the attack. No exploit exists.
Upgrading the affected component is advised.
A vulnerability was found in Apache OFBiz up to 24.09.05. It has been rated as critical. This vulnerability affects unknown code of the component Content Component Operation Handler. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-29226. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in Apache OFBiz up to 24.09.05. This issue affects some unknown processing. Such manipulation leads to cross site scripting.
This vulnerability is referenced as CVE-2026-31379. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability marked as critical has been reported in Apache OFBiz up to 24.09.05. The impacted element is an unknown function. The manipulation leads to improper authentication.
This vulnerability is listed as CVE-2026-31387. The attack must be carried out from within the local network. There is no available exploit.
It is suggested to upgrade the affected component.