VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (152)

  • CVE-2022-0819HigMar 2, 2022
    risk 0.53cvss 8.8epss 0.41

    Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

  • CVE-2026-23500CriApr 17, 2026
    risk 0.52cvss 9.1epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed…

  • CVE-2024-55228CriJan 27, 2025
    risk 0.52cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

  • CVE-2024-55227CriJan 27, 2025
    risk 0.52cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

  • CVE-2021-25955CriAug 15, 2021
    risk 0.52cvss 9.0epss 0.01

    In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are…

  • CVE-2026-31019HigApr 21, 2026
    risk 0.50cvss 8.8epss 0.01

    In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in…

  • CVE-2026-31018HigApr 21, 2026
    risk 0.50cvss 8.8epss 0.00

    In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs…

  • CVE-2025-56588HigOct 1, 2025
    risk 0.50cvss 8.8epss 0.00

    Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.

  • CVE-2021-36625HigMar 31, 2022
    risk 0.50cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

  • CVE-2021-25957HigAug 17, 2021
    risk 0.50cvss 8.8epss 0.01

    In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for…

  • CVE-2020-14443HigJun 18, 2020
    risk 0.50cvss 8.8epss 0.01

    A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands via the id parameter.

  • CVE-2020-12669HigMay 6, 2020
    risk 0.50cvss 8.8epss 0.02

    core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.

  • CVE-2019-11200HigJul 29, 2019
    risk 0.50cvss 8.8epss 0.02

    Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insufficient checks on the export parameters to mysqldump, which can lead to execution of arbitrary binaries on the server. (Malicious…

  • CVE-2018-19998HigJan 3, 2019
    risk 0.50cvss 8.8epss 0.02

    SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.

  • CVE-2018-19994HigJan 3, 2019
    risk 0.50cvss 8.8epss 0.02

    An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.

  • CVE-2019-25452HigFeb 22, 2026
    risk 0.49cvss 7.5epss 0.00

    Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid…

  • CVE-2019-25450HigFeb 22, 2026
    risk 0.49cvss 7.5epss 0.00

    Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and…

  • CVE-2024-31503HigApr 17, 2024
    risk 0.49cvss 7.5epss 0.00

    Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover.

  • CVE-2023-38886HigSep 20, 2023
    risk 0.49cvss 7.2epss 0.29

    An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

  • CVE-2019-19209HigMar 16, 2020
    risk 0.49cvss 7.5epss 0.02

    Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.

Page 3 of 8