OFBiz Known Exploited Vulnerabilities

Evidence-backed KEV intelligence for OFBiz products — CISA KEV status, confidence, sensor telemetry, and virtual-patch availability.

Total KEVs

1

In CISA KEV

0

Beyond CISA KEV

1

Sensor Observed

1

Virtual Patch Available

0

OFBiz KEVs Added by Year

Loading...

1 OFBiz KEV added all time (primary attestation date).

Attested CVEs

CVE Confidence CISA KEV Added
CVE-2011-3600

The /webtools/control/xmlrpc endpoint in OFBiz XML-RPC event handler is exposed to External Entity Injection by passing DOCTYPE declarations with...

Confirmed Not in CISA 05 Jul 2025

Common Vulnerability Classes (CWE)

  • CWE-611 — Improper Restriction of XML External Entity Reference 1

Browse all known exploited vulnerabilities · What is a known exploited vulnerability? · Methodology