August 14, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-59118NVD

Vulnerability Summary

Unrestricted Upload of File with Dangerous Type vulnerability in Apache OFBiz.

This issue affects Apache OFBiz: before 24.09.03.

Users are recommended to upgrade to version 24.09.03, which fixes the issue.
Severity Level
UNKNOWN
Published Date
Nov 12, 2025
Last Modified
Nov 12, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software allows the attacker to upload or transfer files of dangerous types that can be automatically processed within the product's environment.