VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (152)

  • CVE-2019-17223MedOct 15, 2019
    risk 0.33cvss 6.1epss 0.01

    There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

  • CVE-2018-19993MedJan 3, 2019
    risk 0.33cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

  • CVE-2017-17971MedDec 29, 2017
    risk 0.33cvss 6.1epss 0.01

    The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

  • CVE-2015-8685MedJan 15, 2016
    risk 0.33cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.

  • CVE-2022-2060MedJun 13, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2020-13094MedMay 18, 2020
    risk 0.28cvss 5.4epss 0.01

    Dolibarr before 11.0.4 allows XSS.

  • CVE-2018-19995MedJan 3, 2019
    risk 0.28cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

  • CVE-2018-19992MedJan 3, 2019
    risk 0.28cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

  • CVE-2017-14241MedSep 11, 2017
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.

  • CVE-2017-14239MedSep 11, 2017
    risk 0.28cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors,…

  • CVE-2016-1912MedJan 15, 2016
    risk 0.28cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

  • CVE-2024-34051MedJun 3, 2024
    risk 0.24cvss 4.6epss 0.12

    A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

  • CVE-2023-5842MedOct 30, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.

  • CVE-2021-25956MedAug 17, 2021
    risk 0.24cvss 4.7epss 0.01

    In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of…

  • CVE-2026-10215MedJun 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The…

  • CVE-2026-10154MedMay 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to…

  • CVE-2021-3991MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

  • CVE-2022-0746MedFeb 25, 2022
    risk 0.21cvss 4.3epss 0.01

    Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2022-0414MedJan 31, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.

  • CVE-2022-0174MedJan 10, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.

Page 7 of 8