Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Apache OFBiz Path Traversal Vulnerability Leading to Remote Code Execution

Vulnerability

A path traversal vulnerability allowing remote code execution has been identified in Apache OFBiz versions prior to 18.12.13. This vulnerability arises from improper restrictions on file paths, which could be exploited to access unauthorized directories or files.

Impact

Exploitation of this vulnerability could lead to remote code execution on the server where Apache OFBiz is running.

Remediation

Users are advised to upgrade to Apache OFBiz version 18.12.13 or later, which addresses this vulnerability.

Added: Mar 16, 2026, 8:45 PM
Updated: Mar 16, 2026, 8:45 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
9.1
remediation
7.7
relevance
0.0
threat
9.9
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.