VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (152)

  • CVE-2020-11823MedApr 16, 2020
    risk 0.35cvss 5.4epss 0.01

    In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.

  • CVE-2019-19210MedMar 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.

  • CVE-2020-9016MedFeb 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

  • CVE-2019-19206MedNov 26, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.

  • CVE-2019-17578MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

  • CVE-2019-17577MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

  • CVE-2019-17576MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.

  • CVE-2019-16688MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

  • CVE-2019-16687MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

  • CVE-2019-16686MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.

  • CVE-2019-16685MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

  • CVE-2019-11199MedJul 29, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be…

  • CVE-2017-9838MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and…

  • CVE-2017-18259MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.

  • CVE-2017-1000509MedFeb 9, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

  • CVE-2026-19350MedAug 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is…

  • CVE-2026-11619MedJun 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible…

  • CVE-2023-5323MedOct 1, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

  • CVE-2020-14475MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).

  • CVE-2013-2092MedNov 20, 2019
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.

Page 6 of 8