https://seclists.org/oss-sec/2025/q2/2: CVE-2025-30676: Apache OFBiz: Stod XSS Vulnerability
Published Apr 1, 2025
·Updated
Affected Software
1 affected component
Apache OFBiz<18.12.19
Frequently Asked Questions
1
What is the severity of CVE-2025-30676?
The severity of CVE-2025-30676 is moderate.
2
Which versions of Apache OFBiz are affected by CVE-2025-30676?
CVE-2025-30676 affects Apache OFBiz versions before 18.12.19.
3
How do I fix CVE-2025-30676?
To fix CVE-2025-30676, users should upgrade to Apache OFBiz version 18.12.19 or later.
4
What type of vulnerability is CVE-2025-30676?
CVE-2025-30676 is an Improper Neutralization of Script-Related HTML Tags in a Web Page, also known as a Basic XSS vulnerability.
5
When was CVE-2025-30676 published?
CVE-2025-30676 was published on April 1, 2025.