VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (173)

  • CVE-2026-71510MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can…

  • CVE-2026-71509MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity…

  • CVE-2026-71508MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite…

  • CVE-2026-71507MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without…

  • CVE-2026-34036MedMar 31, 2026
    risk 0.35cvss 6.5epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc…

  • CVE-2021-47779MedJan 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an…

  • CVE-2023-4198MedNov 1, 2023
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

  • CVE-2022-0731MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2022-22293MedJan 2, 2022
    risk 0.35cvss 5.4epss 0.01

    admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

  • CVE-2021-42220MedDec 15, 2021
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.

  • CVE-2020-13828MedAug 31, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php…

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-13239MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.

  • CVE-2020-11823MedApr 16, 2020
    risk 0.35cvss 5.4epss 0.01

    In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.

  • CVE-2019-19210MedMar 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.

  • CVE-2020-9016MedFeb 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

  • CVE-2019-19206MedNov 26, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.

  • CVE-2019-17578MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

  • CVE-2019-17577MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

  • CVE-2019-17576MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.

Page 6 of 9