August 14, 2026

CVE Watchtower


← Back to CVE List

CVE-2025-61623NVD

Vulnerability Summary

Reflected cross-site scripting vulnerability in Apache OFBiz.

This issue affects Apache OFBiz: before 24.09.03.

Users are recommended to upgrade to version 24.09.03, which fixes the issue.
Severity Level
UNKNOWN
Published Date
Nov 12, 2025
Last Modified
Nov 12, 2025
Exploitation Status
No confirmed exploitation yet
EPSS Score (30-Day)
Data Pending
Root Weakness (CWE)
The software does not neutralize user-controllable input before it is placed in output that is used as a web page.