CVE-2025-26865

Source
https://cve.org/CVERecord?id=CVE-2025-26865
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26865.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-26865
Published
2025-03-10T14:15:25.220Z
Modified
2026-03-13T22:13:48.672490Z
Severity
  • 3.5 (Low) CVSS_V3 - CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz.

This issue affects Apache OFBiz: from 18.12.17 before 18.12.18.  

It's a regression between 18.12.17 and 18.12.18. In case you use something like that, which is not recommended! For security, only official releases should be used.

In other words, if you use 18.12.17 you are still safe. The version 18.12.17 is not a affected. But something between 18.12.17 and 18.12.18 is.

In that case, users are recommended to upgrade to version 18.12.18, which fixes the issue.

References

Affected packages

Git / github.com/apache/ofbiz-framework

Affected ranges

Type
GIT
Repo
https://github.com/apache/ofbiz-framework
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "18.12.17"
        }
    ]
}

Affected versions

release18.*
release18.12.01
release18.12.02
release18.12.03
release18.12.04
release18.12.05
release18.12.12
release18.12.13
release18.12.14
release18.12.15
release18.12.16
release18.12.17

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-26865.json"