VYPR

Vendor CVEs

Dolibarr

All CVEs

173 total · sorted by risk
  • CVE-2026-71510MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. Attackers can…

  • CVE-2026-71509MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval status and approver identity…

  • CVE-2026-71508MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll columns. Attackers can rewrite…

  • CVE-2026-71507MedAug 24, 2026
    risk 0.35cvss 6.5epss 0.00

    Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without…

  • CVE-2026-34036MedMar 31, 2026
    risk 0.35cvss 6.5epss 0.01

    Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc…

  • CVE-2021-47779MedJan 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded JavaScript that triggers when an…

  • CVE-2023-4198MedNov 1, 2023
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

  • CVE-2022-0731MedFeb 23, 2022
    risk 0.35cvss 6.5epss 0.01

    Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2022-22293MedJan 2, 2022
    risk 0.35cvss 5.4epss 0.01

    admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

  • CVE-2021-42220MedDec 15, 2021
    risk 0.35cvss 5.4epss 0.01

    A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies the payload into a box.

  • CVE-2020-13828MedAug 31, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php…

  • CVE-2020-13240MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

  • CVE-2020-13239MedMay 20, 2020
    risk 0.35cvss 5.4epss 0.01

    The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.

  • CVE-2020-11823MedApr 16, 2020
    risk 0.35cvss 5.4epss 0.01

    In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.

  • CVE-2019-19210MedMar 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.

  • CVE-2020-9016MedFeb 16, 2020
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

  • CVE-2019-19206MedNov 26, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.

  • CVE-2019-17578MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

  • CVE-2019-17577MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

  • CVE-2019-17576MedOct 16, 2019
    risk 0.35cvss 5.4epss 0.01

    An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.

  • CVE-2019-16688MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

  • CVE-2019-16687MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

  • CVE-2019-16686MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.

  • CVE-2019-16685MedSep 27, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

  • CVE-2019-11199MedJul 29, 2019
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be…

  • CVE-2017-9838MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and…

  • CVE-2017-18259MedApr 11, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.

  • CVE-2017-1000509MedFeb 9, 2018
    risk 0.35cvss 5.4epss 0.01

    Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

  • CVE-2026-85401MedSep 4, 2026
    risk 0.34cvss 6.3epss 0.00

    A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipulation can lead to improper…

  • CVE-2026-78160MedAug 24, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23.0.3. This issue affects some unknown processing of the file /user/note.php of the component User Notes Handler. The manipulation of the argument ID leads to authorization bypass. The attack can be initiated…

  • CVE-2026-19930MedAug 16, 2026
    risk 0.34cvss 6.3epss 0.00

    A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the attack remotely. The exploit…

  • CVE-2026-19350MedAug 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability has been found in Dolibarr ERP up to 23.0.3. Affected is the function fail of the file htdocs/takepos/invoice.php of the component TakePOS Module. Such manipulation leads to missing authorization. The attack may be performed from remote. The name of the patch is…

  • CVE-2026-11619MedJun 9, 2026
    risk 0.34cvss 6.3epss 0.00

    A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible…

  • CVE-2026-71503MedAug 24, 2026
    risk 0.33cvss 6.1epss 0.00

    Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted.…

  • CVE-2023-5323MedOct 1, 2023
    risk 0.33cvss 6.1epss 0.00

    Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

  • CVE-2020-14475MedJun 19, 2020
    risk 0.33cvss 6.1epss 0.01

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).

  • CVE-2013-2092MedNov 20, 2019
    risk 0.33cvss 6.1epss 0.01

    Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.

  • CVE-2019-17223MedOct 15, 2019
    risk 0.33cvss 6.1epss 0.01

    There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

  • CVE-2018-19993MedJan 3, 2019
    risk 0.33cvss 6.1epss 0.02

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

  • CVE-2017-17971MedDec 29, 2017
    risk 0.33cvss 6.1epss 0.01

    The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

  • CVE-2015-8685MedJan 15, 2016
    risk 0.33cvss 6.1epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.

  • CVE-2026-77686MedAug 21, 2026
    risk 0.28cvss 5.4epss 0.00

    A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated remotely. The exploit has been…

  • CVE-2022-2060MedJun 13, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.

  • CVE-2020-13094MedMay 18, 2020
    risk 0.28cvss 5.4epss 0.01

    Dolibarr before 11.0.4 allows XSS.

  • CVE-2018-19995MedJan 3, 2019
    risk 0.28cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

  • CVE-2018-19992MedJan 3, 2019
    risk 0.28cvss 5.4epss 0.01

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

  • CVE-2017-14241MedSep 11, 2017
    risk 0.28cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.

  • CVE-2017-14239MedSep 11, 2017
    risk 0.28cvss 5.4epss 0.01

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors,…

  • CVE-2016-1912MedJan 15, 2016
    risk 0.28cvss 5.4epss 0.02

    Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to htdocs/user/card.php.

  • CVE-2024-34051MedJun 3, 2024
    risk 0.24cvss 4.6epss 0.12

    A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.