VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (173)

  • CVE-2019-16688MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

  • CVE-2019-16687MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

  • CVE-2019-16686MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.

  • CVE-2019-16685MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

  • CVE-2019-11199MedJul 29, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be…

  • CVE-2017-9838MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and…

  • CVE-2017-18259MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.

  • CVE-2017-1000509MedFeb 9, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

  • CVE-2026-85401MedSep 4, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper…

  • CVE-2026-78160MedAug 24, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated…

  • CVE-2026-19930MedAug 16, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-19350MedAug 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is…

  • CVE-2026-11619MedJun 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible…

  • CVE-2026-71503MedAug 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted.…

  • CVE-2023-5323MedOct 1, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

  • CVE-2020-14475MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).

  • CVE-2013-2092MedNov 20, 2019
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.

  • CVE-2019-17223MedOct 15, 2019
    risk 0.33cvss 6.1epss 0.01

    There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

  • CVE-2018-19993MedJan 3, 2019
    risk 0.33cvss 6.1epss 0.02

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

  • CVE-2017-17971MedDec 29, 2017
    risk 0.33cvss 6.1epss 0.01

    The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

Page 7 of 9