Dolibarr
by Dolibarr
Source repositories
CVEs (152)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-17223 | Med | 0.33 | 6.1 | 0.01 | Oct 15, 2019 | There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. | ||
| CVE-2018-19993 | Med | 0.33 | 6.1 | 0.01 | Jan 3, 2019 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php. | ||
| CVE-2017-17971 | Med | 0.33 | 6.1 | 0.01 | Dec 29, 2017 | The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS. | ||
| CVE-2015-8685 | Med | 0.33 | 6.1 | 0.02 | Jan 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page. | ||
| CVE-2022-2060 | Med | 0.28 | 5.4 | 0.01 | Jun 13, 2022 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0. | ||
| CVE-2020-13094 | Med | 0.28 | 5.4 | 0.01 | May 18, 2020 | Dolibarr before 11.0.4 allows XSS. | ||
| CVE-2018-19995 | Med | 0.28 | 5.4 | 0.01 | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php. | ||
| CVE-2018-19992 | Med | 0.28 | 5.4 | 0.01 | Jan 3, 2019 | A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php. | ||
| CVE-2017-14241 | Med | 0.28 | 5.4 | 0.01 | Sep 11, 2017 | Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php. | ||
| CVE-2017-14239 | Med | 0.28 | 5.4 | 0.01 | Sep 11, 2017 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors,… | ||
| CVE-2016-1912 | Med | 0.28 | 5.4 | 0.01 | Jan 15, 2016 | Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php. | ||
| CVE-2024-34051 | Med | 0.24 | 4.6 | 0.12 | Jun 3, 2024 | A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter. | ||
| CVE-2023-5842 | Med | 0.24 | 4.8 | 0.00 | Oct 30, 2023 | Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5. | ||
| CVE-2021-25956 | Med | 0.24 | 4.7 | 0.01 | Aug 17, 2021 | In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of… | ||
| CVE-2026-10215 | Med | 0.21 | 4.3 | 0.00 | Jun 1, 2026 | A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The… | ||
| CVE-2026-10154 | Med | 0.21 | 4.3 | 0.00 | May 31, 2026 | A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to… | ||
| CVE-2021-3991 | Med | 0.21 | 4.3 | 0.00 | Nov 15, 2024 | An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions. | ||
| CVE-2022-0746 | Med | 0.21 | 4.3 | 0.01 | Feb 25, 2022 | Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0. | ||
| CVE-2022-0414 | Med | 0.21 | 4.3 | 0.01 | Jan 31, 2022 | Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0. | ||
| CVE-2022-0174 | Med | 0.21 | 4.3 | 0.01 | Jan 10, 2022 | Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr. |
- risk 0.33cvss 6.1epss 0.01
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
- risk 0.33cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.
- risk 0.33cvss 6.1epss 0.01
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
- risk 0.33cvss 6.1epss 0.02
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.
- risk 0.28cvss 5.4epss 0.01
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
- risk 0.28cvss 5.4epss 0.01
Dolibarr before 11.0.4 allows XSS.
- risk 0.28cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.
- risk 0.28cvss 5.4epss 0.01
A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.
- risk 0.28cvss 5.4epss 0.01
Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.
- risk 0.28cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors,…
- risk 0.28cvss 5.4epss 0.01
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.
- risk 0.24cvss 4.6epss 0.12
A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.
- risk 0.24cvss 4.8epss 0.00
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
- risk 0.24cvss 4.7epss 0.01
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of…
- risk 0.21cvss 4.3epss 0.00
A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The…
- risk 0.21cvss 4.3epss 0.00
A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to…
- risk 0.21cvss 4.3epss 0.00
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
- risk 0.21cvss 4.3epss 0.01
Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.
- risk 0.21cvss 4.3epss 0.01
Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.
- risk 0.21cvss 4.3epss 0.01
Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.
Page 7 of 8