VYPR

Vendor CVEs

Dolibarr

All CVEs

152 total · sorted by risk
  • CVE-2023-30253HigMay 29, 2023
    risk 0.67cvss 8.8epss 0.79

    Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

  • CVE-2022-40871CriOct 12, 2022
    risk 0.66cvss 9.8epss 0.33

    Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

  • CVE-2018-10094CriMay 22, 2018
    risk 0.65cvss 9.8epss 0.71

    SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

  • CVE-2012-10059CriAug 13, 2025
    risk 0.64cvss epss 0.03

    Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject arbitrary system commands,…

  • CVE-2021-33816CriNov 10, 2021
    risk 0.64cvss 9.8epss 0.04

    The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

  • CVE-2019-19212CriMar 16, 2020
    risk 0.64cvss 9.8epss 0.04

    Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).

  • CVE-2020-7995CriJan 26, 2020
    risk 0.64cvss 9.8epss 0.05

    The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

  • CVE-2018-16809CriMar 7, 2019
    risk 0.64cvss 9.8epss 0.02

    An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.

  • CVE-2017-7888CriMay 10, 2017
    risk 0.64cvss 9.8epss 0.01

    Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.

  • CVE-2017-7886CriMay 10, 2017
    risk 0.64cvss 9.8epss 0.02

    Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.

  • CVE-2024-5315CriMay 24, 2024
    risk 0.62cvss 9.1epss 0.35

    Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters …

  • CVE-2023-38888CriSep 20, 2023
    risk 0.62cvss 9.6epss 0.01

    Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

  • CVE-2025-69634CriFeb 12, 2026
    risk 0.59cvss 9.0epss 0.00

    Cross Site Request Forgery vulnerability in Dolibarr ERP & CRM v.22.0.9 allows a remote attacker to escalate privileges via the notes field in perms.php NOTE: this is disputed by a third party who indicates that exploitation can only occur if an unprivileged user knows the token…

  • CVE-2024-5314CriMay 24, 2024
    risk 0.59cvss 9.1epss 0.01

    Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters…

  • CVE-2018-25357CriMay 23, 2026
    risk 0.57cvss 9.8epss 0.02

    Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the…

  • CVE-2024-37821HigJun 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.

  • CVE-2024-29477HigApr 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.

  • CVE-2023-38887HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.01

    File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.

  • CVE-2022-4093CriNov 21, 2022
    risk 0.57cvss 9.8epss 0.04

    SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and…

  • CVE-2022-43138CriNov 17, 2022
    risk 0.57cvss 9.8epss 0.01

    Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

  • CVE-2022-0224CriJan 14, 2022
    risk 0.57cvss 9.8epss 0.02

    dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

  • CVE-2020-11825HigApr 16, 2020
    risk 0.57cvss 8.8epss 0.01

    In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

  • CVE-2013-2093CriNov 20, 2019
    risk 0.57cvss 9.8epss 0.05

    Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.

  • CVE-2013-2091CriNov 20, 2019
    risk 0.57cvss 9.8epss 0.03

    SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

  • CVE-2019-1010054HigJul 18, 2019
    risk 0.57cvss 8.8epss 0.02

    Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack…

  • CVE-2018-13450CriJul 8, 2018
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter.

  • CVE-2018-13449CriJul 8, 2018
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter.

  • CVE-2018-13448CriJul 8, 2018
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.

  • CVE-2018-13447CriJul 8, 2018
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

  • CVE-2018-9019CriMay 22, 2018
    risk 0.57cvss 9.8epss 0.04

    SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php,…

  • CVE-2017-9839HigApr 11, 2018
    risk 0.57cvss 8.8epss 0.01

    Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).

  • CVE-2017-18260HigApr 11, 2018
    risk 0.57cvss 8.8epss 0.01

    Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).

  • CVE-2017-17900CriDec 27, 2017
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.

  • CVE-2017-17899CriDec 27, 2017
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.

  • CVE-2017-17897CriDec 27, 2017
    risk 0.57cvss 9.8epss 0.02

    SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

  • CVE-2017-14242CriSep 11, 2017
    risk 0.57cvss 9.8epss 0.01

    SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

  • CVE-2017-14238CriSep 11, 2017
    risk 0.57cvss 9.8epss 0.01

    SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.

  • CVE-2017-9840HigJun 25, 2017
    risk 0.57cvss 8.8epss 0.01

    Dolibarr ERP/CRM 5.0.3 and prior allows low-privilege users to upload files of dangerous types, which can result in arbitrary code execution within the context of the vulnerable application.

  • CVE-2017-9435CriJun 5, 2017
    risk 0.57cvss 9.8epss 0.01

    Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).

  • CVE-2020-14209HigSep 2, 2020
    risk 0.55cvss 8.8epss 0.27

    Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. Also, a .htaccess file can be uploaded to reconfigure access control (e.g., to let .noexe files be…

  • CVE-2022-0819HigMar 2, 2022
    risk 0.53cvss 8.8epss 0.41

    Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

  • CVE-2026-23500CriApr 17, 2026
    risk 0.52cvss 9.1epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed…

  • CVE-2024-55228CriJan 27, 2025
    risk 0.52cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

  • CVE-2024-55227CriJan 27, 2025
    risk 0.52cvss 9.0epss 0.01

    A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

  • CVE-2021-25955CriAug 15, 2021
    risk 0.52cvss 9.0epss 0.01

    In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application users to store malicious scripts in the “Private Note” field at “/adherents/note.php?id=1” endpoint. These scripts are…

  • CVE-2026-31019HigApr 21, 2026
    risk 0.50cvss 8.8epss 0.01

    In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in…

  • CVE-2026-31018HigApr 21, 2026
    risk 0.50cvss 8.8epss 0.00

    In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs…

  • CVE-2025-56588HigOct 1, 2025
    risk 0.50cvss 8.8epss 0.00

    Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.

  • CVE-2021-36625HigMar 31, 2022
    risk 0.50cvss 8.8epss 0.01

    An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

  • CVE-2021-25957HigAug 17, 2021
    risk 0.50cvss 8.8epss 0.01

    In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset the password of any user in the application using the password reset link the user received through email when requested for…

Page 1 of 4