CVE-2020-1943: Apache OFBiz

Medium severity, CVSS 6.1. EPSS: 97.3% chance of exploitation in the next 30 days.

Data sent with contentId to /control/stream is not sanitized, allowing XSS attacks in Apache OFBiz 16.11.01 to 16.11.07.

Affected products

  • Apache OFBiz: from 16.11.01, up to and including 16.11.07

Published 2020-04-01. Last modified 2026-06-17.