VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (173)

  • CVE-2026-81730HigAug 27, 2026
    risk 0.46cvss 8.2epss 0.00

    Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepath = $path . $filename . '.'…

  • CVE-2026-81728HigAug 27, 2026
    risk 0.46cvss 8.1epss 0.00

    Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML but leaves SQL keywords,…

  • CVE-2026-71506HigAug 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payment-issuance rights check.…

  • CVE-2026-71504HigAug 24, 2026
    risk 0.46cvss 8.1epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions.…

  • CVE-2019-25710HigApr 12, 2026
    risk 0.46cvss 8.2epss 0.00

    Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database…

  • CVE-2024-23817HigJan 25, 2024
    risk 0.46cvss 7.1epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and…

  • CVE-2023-33568HigJun 13, 2023
    risk 0.46cvss 7.5epss 0.15

    An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

  • CVE-2021-33618MedNov 10, 2021
    risk 0.46cvss 6.1epss 0.79

    Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.

  • CVE-2019-15062HigAug 14, 2019
    risk 0.45cvss 8.0epss 0.01

    An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is…

  • CVE-2019-11201HigJul 29, 2019
    risk 0.45cvss 8.0epss 0.02

    Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a…

  • CVE-2018-10092HigMay 22, 2018
    risk 0.45cvss 8.0epss 0.02

    The admin panel in Dolibarr before 7.0.2 might allow remote attackers to execute arbitrary commands by leveraging support for updating the antivirus command and parameters used to scan file uploads.

  • CVE-2023-4197HigNov 1, 2023
    risk 0.44cvss 7.5epss 0.33

    Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

  • CVE-2017-8879MedMay 10, 2017
    risk 0.44cvss 6.8epss 0.00

    Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

  • CVE-2018-19799MedDec 26, 2018
    risk 0.43cvss 6.1epss 0.05

    Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.

  • CVE-2026-89013HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.00

    Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a request with hashp=shared to skip…

  • CVE-2020-36966MedJan 30, 2026
    risk 0.42cvss 6.4epss 0.00

    Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to…

  • CVE-2021-37517HigMar 31, 2022
    risk 0.42cvss 7.5epss 0.01

    An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

  • CVE-2020-14201MedAug 21, 2020
    risk 0.42cvss 6.5epss 0.02

    Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/document.php in which "disabled" is changed to "enabled" in the HTML source code.

  • CVE-2017-17898HigDec 27, 2017
    risk 0.42cvss 7.5epss 0.02

    Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.

  • CVE-2017-14240HigSep 11, 2017
    risk 0.42cvss 7.5epss 0.01

    There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.

Page 4 of 9