VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (173)

  • CVE-2026-22666HigApr 7, 2026
    risk 0.41cvss 7.2epss 0.16

    Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator…

  • CVE-2026-37713HigMay 27, 2026
    risk 0.40cvss 7.3epss 0.00

    An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.

  • CVE-2026-37712HigMay 27, 2026
    risk 0.40cvss 7.3epss 0.00

    An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in function job type

  • CVE-2026-37711HigMay 27, 2026
    risk 0.40cvss 7.3epss 0.00

    An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php

  • CVE-2025-67486HigMay 8, 2026
    risk 0.40cvss 7.2epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the…

  • CVE-2022-30875MedJun 8, 2022
    risk 0.40cvss 6.1epss 0.01

    Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

  • CVE-2020-35136HigDec 23, 2020
    risk 0.40cvss 7.2epss 0.07

    Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.

  • CVE-2019-19211MedMar 16, 2020
    risk 0.40cvss 6.1epss 0.02

    Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.

  • CVE-2020-7996MedJan 26, 2020
    risk 0.40cvss 6.1epss 0.01

    htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.

  • CVE-2020-7994MedJan 26, 2020
    risk 0.40cvss 6.1epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the…

  • CVE-2019-1010016MedJul 15, 2019
    risk 0.40cvss 6.1epss 0.01

    Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.

  • CVE-2018-16808MedMar 7, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

  • CVE-2017-7887MedMay 10, 2017
    risk 0.40cvss 6.1epss 0.01

    Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.

  • CVE-2026-71505HigAug 24, 2026
    risk 0.39cvss 7.1epss 0.00

    Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any company by bypassing per-object…

  • CVE-2018-10095MedMay 22, 2018
    risk 0.38cvss 6.1epss 0.69

    Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/carte.php.

  • CVE-2024-40137MedJul 24, 2024
    risk 0.36cvss 5.5epss 0.01

    Dolibarr ERP CRM before 19.0.2-php8.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.

  • CVE-2019-16197MedSep 16, 2019
    risk 0.36cvss 6.1epss 0.03

    In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

  • CVE-2026-89012MedSep 11, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected field names. Attackers can…

  • CVE-2026-81729MedAug 27, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE /api/index.php/documents, while…

  • CVE-2026-71511MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the individual member or member list…

Page 5 of 9