VYPR

Dolibarr

by Dolibarr

Source repositories

CVEs (173)

  • CVE-2015-8685MedJan 15, 2016
    risk 0.33cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.

  • CVE-2026-77686MedAug 21, 2026
    risk 0.28cvss 5.4epss 0.00

    A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated remotely. The exploit has been…

  • CVE-2022-2060MedJun 13, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2020-13094MedMay 18, 2020
    risk 0.28cvss 5.4epss 0.01

    Dolibarr before 11.0.4 allows XSS.

  • CVE-2018-19995MedJan 3, 2019
    risk 0.28cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

  • CVE-2018-19992MedJan 3, 2019
    risk 0.28cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

  • CVE-2017-14241MedSep 11, 2017
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.

  • CVE-2017-14239MedSep 11, 2017
    risk 0.28cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors,…

  • CVE-2016-1912MedJan 15, 2016
    risk 0.28cvss 5.4epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

  • CVE-2024-34051MedJun 3, 2024
    risk 0.24cvss 4.6epss 0.12

    A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.

  • CVE-2023-5842MedOct 30, 2023
    risk 0.24cvss 4.8epss 0.00

    Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.

  • CVE-2021-25956MedAug 17, 2021
    risk 0.24cvss 4.7epss 0.01

    In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of…

  • CVE-2026-82633MedAug 30, 2026
    risk 0.21cvss 4.3epss 0.00

    Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers…

  • CVE-2026-77923MedAug 24, 2026
    risk 0.21cvss 4.3epss 0.00

    Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authenticated users with project…

  • CVE-2026-10215MedJun 1, 2026
    risk 0.21cvss 4.3epss 0.00

    A security vulnerability has been detected in Dolibarr ERP CRM up to 23.0.1. Impacted is the function checkUserAccessToObject of the file htdocs/holiday/class/api_holidays.class.php of the component Leave Request REST API. The manipulation leads to improper authorization. The…

  • CVE-2026-10154MedMay 31, 2026
    risk 0.21cvss 4.3epss 0.00

    A vulnerability has been found in Dolibarr ERP CRM 23.0.0/23.0.1/23.0.2. The affected element is an unknown function of the file htdocs/user/messaging.php. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. Upgrading to…

  • CVE-2021-3991MedNov 15, 2024
    risk 0.21cvss 4.3epss 0.00

    An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

  • CVE-2022-0746MedFeb 25, 2022
    risk 0.21cvss 4.3epss 0.01

    Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2022-0414MedJan 31, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.

  • CVE-2022-0174MedJan 10, 2022
    risk 0.21cvss 4.3epss 0.01

    Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.

Page 8 of 9