VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (152)

  • CVE-2022-30875MedJun 8, 2022
    risk 0.40cvss 6.1epss 0.01

    Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

  • CVE-2020-35136HigDec 23, 2020
    risk 0.40cvss 7.2epss 0.06

    Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.

  • CVE-2019-19211MedMar 16, 2020
    risk 0.40cvss 6.1epss 0.02

    Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.

  • CVE-2020-7996MedJan 26, 2020
    risk 0.40cvss 6.1epss 0.01

    htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.

  • CVE-2020-7994MedJan 26, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the…

  • CVE-2019-1010016MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.01

    Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.

  • CVE-2018-16808MedMar 7, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

  • CVE-2018-10095MedMay 22, 2018
    risk 0.40cvss 6.1epss 0.87

    Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.

  • CVE-2017-7887MedMay 10, 2017
    risk 0.40cvss 6.1epss 0.01

    Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.

  • CVE-2024-40137MedJul 24, 2024
    risk 0.36cvss 5.5epss 0.01

    Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

  • CVE-2019-16197MedSep 16, 2019
    risk 0.36cvss 6.1epss 0.03

    In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

  • CVE-2026-34036MedMar 31, 2026
    risk 0.35cvss 6.5epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc…

  • CVE-2021-47779MedJan 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an…

  • CVE-2023-4198MedNov 1, 2023
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

  • CVE-2022-0731MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2022-22293MedJan 2, 2022
    risk 0.35cvss 5.4epss 0.01

    admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

  • CVE-2021-42220MedDec 15, 2021
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.

  • CVE-2020-13828MedAug 31, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php…

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-13239MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.

Page 5 of 8