Dolibarr
by Dolibarr
Source repositories
CVEs (173)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-16688 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.) | ||
| CVE-2019-16687 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation. | ||
| CVE-2019-16686 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin. | ||
| CVE-2019-16685 | Med | 0.35 | 5.4 | 0.01 | Sep 27, 2019 | Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation. | ||
| CVE-2019-11199 | Med | 0.35 | 5.4 | 0.01 | Jul 29, 2019 | Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be… | ||
| CVE-2017-9838 | Med | 0.35 | 5.4 | 0.01 | Apr 11, 2018 | Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and… | ||
| CVE-2017-18259 | Med | 0.35 | 5.4 | 0.01 | Apr 11, 2018 | Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0. | ||
| CVE-2017-1000509 | Med | 0.35 | 5.4 | 0.01 | Feb 9, 2018 | Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code. | ||
| CVE-2026-85401 | Med | 0.34 | 6.3 | 0.00 | Sep 4, 2026 | A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper… | ||
| CVE-2026-78160 | Med | 0.34 | 6.3 | 0.00 | Aug 24, 2026 | A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated… | ||
| CVE-2026-19930 | Med | 0.34 | 6.3 | 0.00 | Aug 16, 2026 | A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit… | ||
| CVE-2026-19350 | Med | 0.34 | 6.3 | 0.00 | Aug 9, 2026 | A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is… | ||
| CVE-2026-11619 | Med | 0.34 | 6.3 | 0.00 | Jun 9, 2026 | A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible… | ||
| CVE-2026-71503 | Med | 0.33 | 6.1 | 0.00 | Aug 24, 2026 | Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted.… | ||
| CVE-2023-5323 | Med | 0.33 | 6.1 | 0.00 | Oct 1, 2023 | Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0. | ||
| CVE-2020-14475 | Med | 0.33 | 6.1 | 0.01 | Jun 19, 2020 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey). | ||
| CVE-2013-2092 | Med | 0.33 | 6.1 | 0.01 | Nov 20, 2019 | Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php. | ||
| CVE-2019-17223 | Med | 0.33 | 6.1 | 0.01 | Oct 15, 2019 | There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. | ||
| CVE-2018-19993 | Med | 0.33 | 6.1 | 0.02 | Jan 3, 2019 | A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php. | ||
| CVE-2017-17971 | Med | 0.33 | 6.1 | 0.01 | Dec 29, 2017 | The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS. |
- risk 0.35cvss 5.4epss 0.01
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)
- risk 0.35cvss 5.4epss 0.01
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
- risk 0.35cvss 5.4epss 0.01
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
- risk 0.35cvss 5.4epss 0.01
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
- risk 0.35cvss 5.4epss 0.01
Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be…
- risk 0.35cvss 5.4epss 0.01
Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and…
- risk 0.35cvss 5.4epss 0.01
Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.
- risk 0.35cvss 5.4epss 0.01
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.
- risk 0.34cvss 6.3epss 0.00
A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper…
- risk 0.34cvss 6.3epss 0.00
A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated…
- risk 0.34cvss 6.3epss 0.00
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit…
- risk 0.34cvss 6.3epss 0.00
A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is…
- risk 0.34cvss 6.3epss 0.00
A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible…
- risk 0.33cvss 6.1epss 0.00
Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted.…
- risk 0.33cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
- risk 0.33cvss 6.1epss 0.01
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).
- risk 0.33cvss 6.1epss 0.01
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
- risk 0.33cvss 6.1epss 0.01
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
- risk 0.33cvss 6.1epss 0.02
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.
- risk 0.33cvss 6.1epss 0.01
The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.
Page 7 of 9