CVE-2026-31906: Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog Parameters
Published May 19, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
Affected Software
2 affected components
Apache OFBiz<24.09.06
Apache OFBiz<24.09.06
Event History
May 19, 2026
CVE Published
via MITRE·09:30 AM
Data Sourced
via MITRE·09:30 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-31906?
The severity of CVE-2026-31906 is medium with a CVSS score of 6.1.
2
How do I fix CVE-2026-31906?
To fix CVE-2026-31906, users should upgrade Apache OFBiz to version 24.09.06 or later.
3
What type of vulnerability is CVE-2026-31906?
CVE-2026-31906 is classified as a Cross-site Scripting (XSS) vulnerability due to improper HTML attribute escaping.
4
Which versions of Apache OFBiz are affected by CVE-2026-31906?
CVE-2026-31906 affects Apache OFBiz versions prior to 24.09.06.
5
What are the potential impacts of CVE-2026-31906?
The potential impacts of CVE-2026-31906 include unauthorized access to sensitive information and the execution of malicious scripts in the user's browser.