#OFBiz
Apache OFBiz 24.09.04 is now available for download: buff.ly/c7gf19L

OFBiz is an #opensource platform for the automation of enterprise processes, including framework components and business applications.
December 10, 2025 at 3:01 PM
Apache OFBiz is an #opensource platform for the automation of enterprise processes, including framework components and business applications.

Apache OFBiz 24.09.05 is now available for download: buff.ly/QBr0lqB
February 19, 2026 at 12:15 PM
🚨Apache OFBiz Exploit - CVE-2024-38856

🔗 PoC: github.com/AlissonFaoli...
🛑 CVE: CVE-2024-38856
💻 Affected: Apache OFBiz ≤ 18.12.14
⚠️ Type: Remote Code Execution (RCE)
🔓 Exploitation: No authentication required
GitHub - AlissonFaoli/Apache-OFBiz-Exploit: Exploit for Apache OFBiz - CVE-2024-38856
Exploit for Apache OFBiz - CVE-2024-38856. Contribute to AlissonFaoli/Apache-OFBiz-Exploit development by creating an account on GitHub.
github.com
February 11, 2025 at 6:07 PM
Apaches Entwickler haben in der Unternehmenssoftware OFBiz mehrere teilweise kritische Sicherheitslücken geschlossen. #Security
Sicherheitsupdate: Hartkodierter Schlüssel ermöglicht Zugriffe auf Apache OFBiz
Apaches Entwickler haben in der Unternehmenssoftware OFBiz mehrere teilweise kritische Sicherheitslücken geschlossen.
www.heise.de
May 20, 2026 at 10:12 AM
Apache OFBiz 24.09.03 is now available for download: buff.ly/Wz34Rcl

Apache OFBiz® is an #opensource platform for the automation of enterprise processes, including framework components and business applications. #opensource
November 14, 2025 at 10:57 PM
CISA warnt vor Angriffen auf Linux, Apache OFBiz, .NET und Paessler PRTG

In der Nacht zum Donnerstag hat die CISA eine Warnung vor einer bei einem Angriff missbrauchten Sicherheitslücke im Linux-Kernel herausgegeben. Die Schwachstelle betrifft den USB-Video-Class-Treiber (UVC).....
CISA warnt vor Angriffen auf Linux, Apache OFBiz, .NET und Paessler PRTG
DIe US-amerikanische Cybersicherheitsbehörde CISA warnt vor beobachteten Angriffen auf Lücken in Linux, Apache OFBiz, .NET und Paessler PRTG.
www.heise.de
February 6, 2025 at 10:03 PM
Sicherheitsupdate: Hartkodierter Schlüssel ermöglicht Zugriffe auf Apache OFBiz | Security www.heise.de/news/Sicherh...
Sicherheitsupdate: Hartkodierter Schlüssel ermöglicht Zugriffe auf Apache OFBiz
Apaches Entwickler haben in der Unternehmenssoftware OFBiz mehrere teilweise kritische Sicherheitslücken geschlossen.
www.heise.de
May 24, 2026 at 5:11 PM
U.S. CISA adds Microsoft .NET Framework, Apache OFBiz, and Paessler PRTG Network Monitor flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Microsoft .NET Framework, Apache OFBiz, and Paessler PRTG Network Monitor flaws to its Known Exploited Vulnerabilities catalog
U.S. CISA adds Microsoft .NET Framework, Apache OFBiz, and Paessler PRTG Network Monitor flaws to its Known Exploited Vulnerabilities catalog.
securityaffairs.com
February 5, 2025 at 4:14 PM
Apache OFBiz

ofbiz.apache.org
The Apache OFBiz® Project
ofbiz.apache.org
May 20, 2025 at 6:04 PM
Apache OFBiz 24.09.06 is now available for download: buff.ly/K7WW8ZL

OFBiz is an open source platform for the automation of enterprise processes, including framework components and business applications.

For more information, visit: buff.ly/oL8ao11
May 31, 2026 at 3:01 PM
CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks
CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks
The US Cybersecurity & Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies and large organizations to apply the available security updates as soon as possible.
www.bleepingcomputer.com
February 5, 2025 at 5:10 PM
Auf Sicherheitslücken im Android-Kernel, Apache OfBiz und Progress WhatsUp finden inzwischen Angriffe in freier Wildbahn statt. #Security
Angriffe auf Android-Kernel, Apache OfBiz und Progress WhatsUp
Auf Sicherheitslücken im Android-Kernel, Apache OfBiz und Progress WhatsUp finden inzwischen Angriffe in freier Wildbahn statt.
www.heise.de
August 8, 2024 at 10:12 AM
CVE-2025-26865: Apache OFBiz Vulnerability Could Lead to Remote Code Execution securityonline.info/cve-2025-268...
CVE-2025-26865: Apache OFBiz Vulnerability Could Lead to Remote Code Execution
Learn about CVE-2025-26865, a vulnerability in Apache OFBiz that allows arbitrary code execution on vulnerable servers.
securityonline.info
March 12, 2025 at 7:49 AM
Notícia da BleepingComputer

"CISA marca bugs do Microsoft .NET e Apache OFBiz como explorados em ataques" #bolhasec
CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks
The US Cybersecurity & Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies and large organizations to apply the...
www.bleepingcomputer.com
February 8, 2025 at 3:30 PM
Apache OFBiz 24.09.01 is now available for download: buff.ly/1XGlzXO

OFBiz is an #opensource platform for the automation of enterprise processes, including framework components and business applications.
April 15, 2025 at 9:25 PM
Eine aktualisierte Version der ERP-Software Apache OfBiz schließt Sicherheitslecks, die das Ausführen von Schadcode ermöglichen. #Security
Apache OfBiz: Schwachstelle ermöglicht Codeschmuggel
Eine aktualisierte Version der ERP-Software Apache OfBiz schließt Sicherheitslecks, die das Ausführen von Schadcode ermöglichen.
www.heise.de
November 20, 2024 at 7:50 AM
Apache OFBiz 18.12.19 is now available for download.

OFBiz is an #opensource platform for the automation of enterprise processes, including framework components and business applications.

To download: buff.ly/pv4lSZT
April 8, 2025 at 11:18 PM
Practical Exploitation of XXE(CVE-2018–8033) and Mitigating in Apache OFBiz
Practical Exploitation of XXE(CVE-2018–8033) and Mitigating in Apache OFBiz
Introduction
infosecwriteups.com
March 15, 2024 at 12:57 PM
CISA added 4 critical vulnerabilities (CVSS up to 9.8) to its KEV catalog, impacting Apache OFBiz, Microsoft .NET, & Paessler PRTG. Fixes are urged by Feb 25, 2025. Vendor patches available.#CriticalVulnerabilityPatchNow
February 5, 2025 at 6:05 AM
SonicWall has recently uncovered a new Apache OFBiz RCE vulnerability (CVE-2023-51467): 
blog.sonicwall.com/en-us/2023/1...

The vulnerability is apparently due to an incomplete fix for CVE-2023-49070 (CVSS 9.8 pre-auth RCE) that was patched Dec 4th: issues.apache.org/jira/browse/...
December 28, 2023 at 11:09 AM
He said I’ll get you $$$&! Vote for meeee! So they did. They voted for a child grapist for promise of a buck. Surprise! He got into office and said bendover, cuz we’re driving you out ofbiz and then the AcreTrader Vance is taking your multi-generation farm.
October 12, 2025 at 1:47 AM
New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems thehackernews.com/20... #cybersecurity #infosec #privacy #news
New PoC Exploit for Apache OfBiz Vulnerability Poses Risk to ERP Systems
Researchers expose critical flaw in Apache OFBiz, CVE-2023-51467, enabling stealthy memory-resident attacks
thehackernews.com
January 11, 2024 at 3:17 PM
ID: CVE-2024-47208
CVSS N/A
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version...
#security #infosec #cve-alert
nvd.nist.gov
November 18, 2024 at 9:15 AM