dolibarr CVE Vulnerabilities & Metrics

Focus on dolibarr vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About dolibarr Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with dolibarr. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total dolibarr CVEs: 91
Earliest CVE date: 28 Nov 2011, 11:55 UTC
Latest CVE date: 27 Jan 2025, 17:15 UTC

Latest CVE reference: CVE-2024-55228

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 5

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): -100.0%
Year Variation (Calendar): -50.0%

Month Growth Rate (30-day Rolling): -100.0%
Year Growth Rate (365-day Rolling): -50.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical dolibarr CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.35

Max CVSS: 10.0

Critical CVEs (≥9): 3

CVSS Range vs. Count

Range Count
0.0-3.9 40
4.0-6.9 39
7.0-8.9 16
9.0-10.0 3

CVSS Distribution Chart

Top 5 Highest CVSS dolibarr CVEs

These are the five CVEs with the highest CVSS scores for dolibarr, sorted by severity first and recency.

All CVEs for dolibarr

CVE-2024-55228 dolibarr vulnerability CVSS: 0 27 Jan 2025, 17:15 UTC

A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

CVE-2024-55227 dolibarr vulnerability CVSS: 0 27 Jan 2025, 17:15 UTC

A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.

CVE-2021-3991 dolibarr vulnerability CVSS: 0 15 Nov 2024, 11:15 UTC

An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.

CVE-2024-5315 dolibarr vulnerability CVSS: 0 24 May 2024, 10:15 UTC

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php.

CVE-2024-5314 dolibarr vulnerability CVSS: 0 24 May 2024, 10:15 UTC

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.

CVE-2024-23817 dolibarr vulnerability CVSS: 0 25 Jan 2024, 20:15 UTC

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifically, I was able to successfully inject a new HTML tag into the returned document and, as a result, was able to comment out some part of the Dolibarr App Home page HTML code. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS). To remediate the issue, validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks; and implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML.

CVE-2023-4198 dolibarr vulnerability CVSS: 0 01 Nov 2023, 09:15 UTC

Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

CVE-2023-4197 dolibarr vulnerability CVSS: 0 01 Nov 2023, 08:15 UTC

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

CVE-2023-5842 dolibarr vulnerability CVSS: 0 30 Oct 2023, 01:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.

CVE-2023-5323 dolibarr vulnerability CVSS: 0 01 Oct 2023, 01:15 UTC

Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

CVE-2023-38888 dolibarr vulnerability CVSS: 0 20 Sep 2023, 01:15 UTC

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.

CVE-2023-38887 dolibarr vulnerability CVSS: 0 20 Sep 2023, 01:15 UTC

File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.

CVE-2023-38886 dolibarr vulnerability CVSS: 0 20 Sep 2023, 01:15 UTC

An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

CVE-2023-33568 dolibarr vulnerability CVSS: 0 13 Jun 2023, 15:15 UTC

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.

CVE-2023-30253 dolibarr vulnerability CVSS: 0 29 May 2023, 21:15 UTC

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

CVE-2022-4093 dolibarr vulnerability CVSS: 0 21 Nov 2022, 05:15 UTC

SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many high-profile data breaches in recent years have been the result of SQL injection attacks, leading to reputational damage and regulatory fines. In some cases, an attacker can obtain a persistent backdoor into an organization's systems, leading to a long-term compromise that can go unnoticed for an extended period. This affect 16.0.1 and 16.0.2 only. 16.0.0 or lower, and 16.0.3 or higher are not affected

CVE-2022-43138 dolibarr vulnerability CVSS: 0 17 Nov 2022, 17:15 UTC

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

CVE-2022-40871 dolibarr vulnerability CVSS: 0 12 Oct 2022, 12:15 UTC

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.

CVE-2022-2060 dolibarr vulnerability CVSS: 3.5 13 Jun 2022, 09:15 UTC

Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-30875 dolibarr vulnerability CVSS: 4.3 08 Jun 2022, 17:15 UTC

Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

CVE-2021-37517 dolibarr vulnerability CVSS: 5.0 31 Mar 2022, 19:15 UTC

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application allows email addresses as usernames, which can cause a Denial of Service.

CVE-2021-36625 dolibarr vulnerability CVSS: 6.5 31 Mar 2022, 18:15 UTC

An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDATE statement.

CVE-2022-0819 dolibarr vulnerability CVSS: 6.5 02 Mar 2022, 16:15 UTC

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

CVE-2022-0746 dolibarr vulnerability CVSS: 4.0 25 Feb 2022, 09:15 UTC

Business Logic Errors in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-0731 dolibarr vulnerability CVSS: 4.0 23 Feb 2022, 19:15 UTC

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

CVE-2022-0414 dolibarr vulnerability CVSS: 4.0 31 Jan 2022, 11:15 UTC

Improper Validation of Specified Quantity in Input in Packagist dolibarr/dolibarr prior to 16.0.

CVE-2022-0224 dolibarr vulnerability CVSS: 7.5 14 Jan 2022, 18:15 UTC

dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

CVE-2022-0174 dolibarr vulnerability CVSS: 4.0 10 Jan 2022, 18:15 UTC

Improper Validation of Specified Quantity in Input vulnerability in dolibarr dolibarr/dolibarr.

CVE-2022-22293 dolibarr vulnerability CVSS: 3.5 02 Jan 2022, 00:15 UTC

admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

CVE-2021-33816 dolibarr vulnerability CVSS: 7.5 10 Nov 2021, 23:15 UTC

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.

CVE-2021-33618 dolibarr vulnerability CVSS: 4.3 10 Nov 2021, 23:15 UTC

Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.

CVE-2021-25956 dolibarr vulnerability CVSS: 6.5 17 Aug 2021, 15:15 UTC

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to validate already existing “Login” name, while renaming the user “Login”. This leads to complete account takeover of the victim user. This happens since the password gets overwritten for the victim user having a similar login name.

CVE-2020-35136 dolibarr vulnerability CVSS: 9.0 23 Dec 2020, 15:15 UTC

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup function by inserting a payload into the filename for the zipfilename_template parameter to admin/tools/dolibarr_export.php.

CVE-2020-13828 dolibarr vulnerability CVSS: 3.5 31 Aug 2020, 16:15 UTC

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card.php with the societe or address parameter; product/card.php with the label or customcode parameter; or societe/card.php with the alias or barcode parameter.

CVE-2020-14475 dolibarr vulnerability CVSS: 4.3 19 Jun 2020, 17:15 UTC

A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/notice.php (related to transphrase and transkey).

CVE-2020-13240 dolibarr vulnerability CVSS: 5.5 20 May 2020, 15:15 UTC

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.

CVE-2020-13239 dolibarr vulnerability CVSS: 3.5 20 May 2020, 15:15 UTC

The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.

CVE-2020-11825 dolibarr vulnerability CVSS: 6.8 16 Apr 2020, 19:15 UTC

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.

CVE-2020-11823 dolibarr vulnerability CVSS: 3.5 16 Apr 2020, 19:15 UTC

In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.

CVE-2020-9016 dolibarr vulnerability CVSS: 3.5 16 Feb 2020, 22:15 UTC

Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

CVE-2020-7996 dolibarr vulnerability CVSS: 4.3 26 Jan 2020, 23:15 UTC

htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.

CVE-2020-7995 dolibarr vulnerability CVSS: 10.0 26 Jan 2020, 23:15 UTC

The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

CVE-2020-7994 dolibarr vulnerability CVSS: 4.3 26 Jan 2020, 23:15 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the /htdocs/admin/const.php?mainmenu=home page; the (3) note[note] parameter to the /htdocs/admin/dict.php?id=10 page; the (4) zip[MAIN_INFO_SOCIETE_ZIP] or email[mail] parameter to the /htdocs/admin/company.php page; the (5) url[defaulturl], field[defaultkey], or value[defaultvalue] parameter to the /htdocs/admin/defaultvalues.php page; the (6) key[transkey] or key[transvalue] parameter to the /htdocs/admin/translation.php page; or the (7) [main_motd] or [main_home] parameter to the /htdocs/admin/ihm.php page.

CVE-2019-19206 dolibarr vulnerability CVSS: 3.5 26 Nov 2019, 15:15 UTC

Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.

CVE-2013-2093 dolibarr vulnerability CVSS: 10.0 20 Nov 2019, 21:15 UTC

Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.

CVE-2013-2092 dolibarr vulnerability CVSS: 4.3 20 Nov 2019, 21:15 UTC

Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.

CVE-2013-2091 dolibarr vulnerability CVSS: 7.5 20 Nov 2019, 20:15 UTC

SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.

CVE-2019-17578 dolibarr vulnerability CVSS: 3.5 16 Oct 2019, 18:15 UTC

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.

CVE-2019-17577 dolibarr vulnerability CVSS: 3.5 16 Oct 2019, 18:15 UTC

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.

CVE-2019-17576 dolibarr vulnerability CVSS: 3.5 16 Oct 2019, 18:15 UTC

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.

CVE-2019-17223 dolibarr vulnerability CVSS: 4.3 15 Oct 2019, 12:15 UTC

There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

CVE-2019-16688 dolibarr vulnerability CVSS: 3.5 27 Sep 2019, 20:15 UTC

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)

CVE-2019-16687 dolibarr vulnerability CVSS: 3.5 27 Sep 2019, 20:15 UTC

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

CVE-2019-16686 dolibarr vulnerability CVSS: 3.5 27 Sep 2019, 20:15 UTC

Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.

CVE-2019-16685 dolibarr vulnerability CVSS: 3.5 27 Sep 2019, 20:15 UTC

Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.

CVE-2019-16197 dolibarr vulnerability CVSS: 4.3 16 Sep 2019, 13:15 UTC

In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, leading to XSS.

CVE-2019-15062 dolibarr vulnerability CVSS: 6.0 14 Aug 2019, 23:15 UTC

An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files settings page. When visited by the admin, this could completely take over the admin account. (The protection mechanism for CSRF is to check the Referer header; however, because the attack is from one of the application's own settings pages, this mechanism is bypassed.)

CVE-2019-11201 dolibarr vulnerability CVSS: 8.5 29 Jul 2019, 16:15 UTC

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.

CVE-2019-11200 dolibarr vulnerability CVSS: 6.5 29 Jul 2019, 16:15 UTC

Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insufficient checks on the export parameters to mysqldump, which can lead to execution of arbitrary binaries on the server. (Malicious binaries can be uploaded by abusing other functionalities of the application.)

CVE-2019-11199 dolibarr vulnerability CVSS: 3.5 29 Jul 2019, 16:15 UTC

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each time any regular user or administrative user clicked on the malicious link hosted on the same domain. The vulnerabilities could be exploited by low privileged users to target administrators. The viewimage.php page did not perform any contextual output encoding and would display the content within the uploaded file with a user-requested MIME type.

CVE-2019-1010054 dolibarr vulnerability CVSS: 6.8 18 Jul 2019, 13:15 UTC

Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disable password encryptation. The component is: Function User password change, user disable and password encryptation. The attack vector is: admin access malitious urls.

CVE-2019-1010016 dolibarr vulnerability CVSS: 4.3 15 Jul 2019, 03:15 UTC

Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attack vector is: Victim must click a specially crafted link sent by the attacker.

CVE-2018-19998 dolibarr vulnerability CVSS: 6.5 03 Jan 2019, 19:29 UTC

SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.

CVE-2018-19995 dolibarr vulnerability CVSS: 3.5 03 Jan 2019, 19:29 UTC

A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

CVE-2018-19994 dolibarr vulnerability CVSS: 6.5 03 Jan 2019, 19:29 UTC

An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.

CVE-2018-19993 dolibarr vulnerability CVSS: 4.3 03 Jan 2019, 19:29 UTC

A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

CVE-2018-19992 dolibarr vulnerability CVSS: 3.5 03 Jan 2019, 19:29 UTC

A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

CVE-2018-13450 dolibarr vulnerability CVSS: 7.5 08 Jul 2018, 16:29 UTC

SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter.

CVE-2018-13449 dolibarr vulnerability CVSS: 7.5 08 Jul 2018, 16:29 UTC

SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter.

CVE-2018-13448 dolibarr vulnerability CVSS: 7.5 08 Jul 2018, 16:29 UTC

SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.

CVE-2018-13447 dolibarr vulnerability CVSS: 7.5 08 Jul 2018, 16:29 UTC

SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

CVE-2017-9839 dolibarr vulnerability CVSS: 6.5 11 Apr 2018, 03:29 UTC

Dolibarr ERP/CRM is affected by SQL injection in versions before 5.0.4 via product/stats/card.php (type parameter).

CVE-2017-9838 dolibarr vulnerability CVSS: 3.5 11 Apr 2018, 03:29 UTC

Dolibarr ERP/CRM is affected by multiple reflected Cross-Site Scripting (XSS) vulnerabilities in versions before 5.0.4: index.php (leftmenu parameter), core/ajax/box.php (PATH_INFO), product/stats/card.php (type parameter), holiday/list.php (month_create, month_start, and month_end parameters), and don/card.php (societe, lastname, firstname, address, zipcode, town, and email parameters).

CVE-2017-18260 dolibarr vulnerability CVSS: 6.5 11 Apr 2018, 03:29 UTC

Dolibarr ERP/CRM is affected by multiple SQL injection vulnerabilities in versions through 7.0.0 via comm/propal/list.php (viewstatut parameter) or comm/propal/list.php (propal_statut parameter, aka search_statut parameter).

CVE-2017-18259 dolibarr vulnerability CVSS: 3.5 11 Apr 2018, 03:29 UTC

Dolibarr ERP/CRM is affected by stored Cross-Site Scripting (XSS) in versions through 7.0.0.

CVE-2017-1000509 dolibarr vulnerability CVSS: 3.5 09 Feb 2018, 23:29 UTC

Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

CVE-2017-17971 dolibarr vulnerability CVSS: 4.3 29 Dec 2017, 18:29 UTC

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscroll, which allows XSS.

CVE-2017-17900 dolibarr vulnerability CVSS: 7.5 27 Dec 2017, 17:08 UTC

SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.

CVE-2017-17899 dolibarr vulnerability CVSS: 7.5 27 Dec 2017, 17:08 UTC

SQL injection vulnerability in adherents/subscription/info.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the rowid parameter.

CVE-2017-17898 dolibarr vulnerability CVSS: 5.0 27 Dec 2017, 17:08 UTC

Dolibarr ERP/CRM version 6.0.4 does not block direct requests to *.tpl.php files, which allows remote attackers to obtain sensitive information.

CVE-2017-17897 dolibarr vulnerability CVSS: 7.5 27 Dec 2017, 17:08 UTC

SQL injection vulnerability in comm/multiprix.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the id parameter.

CVE-2017-14242 dolibarr vulnerability CVSS: 7.5 11 Sep 2017, 09:29 UTC

SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.

CVE-2017-14241 dolibarr vulnerability CVSS: 3.5 11 Sep 2017, 09:29 UTC

Cross-site scripting (XSS) vulnerability in Dolibarr ERP/CRM 6.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the Title parameter to htdocs/admin/menus/edit.php.

CVE-2017-14240 dolibarr vulnerability CVSS: 5.0 11 Sep 2017, 09:29 UTC

There is a sensitive information disclosure vulnerability in document.php in Dolibarr ERP/CRM version 6.0.0 via the file parameter.

CVE-2017-14239 dolibarr vulnerability CVSS: 3.5 11 Sep 2017, 09:29 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 6.0.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) CompanyName, (2) CompanyAddress, (3) CompanyZip, (4) CompanyTown, (5) Fax, (6) EMail, (7) Web, (8) ManagingDirectors, (9) Note, (10) Capital, (11) ProfId1, (12) ProfId2, (13) ProfId3, (14) ProfId4, (15) ProfId5, or (16) ProfId6 parameter to htdocs/admin/company.php.

CVE-2017-14238 dolibarr vulnerability CVSS: 7.5 11 Sep 2017, 09:29 UTC

SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.

CVE-2017-8879 dolibarr vulnerability CVSS: 4.6 10 May 2017, 14:29 UTC

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to obtain access via an unattended workstation.

CVE-2017-7888 dolibarr vulnerability CVSS: 5.0 10 May 2017, 14:29 UTC

Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.

CVE-2017-7887 dolibarr vulnerability CVSS: 4.3 10 May 2017, 14:29 UTC

Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.

CVE-2017-7886 dolibarr vulnerability CVSS: 7.5 10 May 2017, 14:29 UTC

Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.

CVE-2015-3935 dolibarr vulnerability CVSS: 4.3 10 Jun 2015, 14:59 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (search_nom) field to (1) htdocs/societe/societe.php or (2) htdocs/societe/admin/societe.php.

CVE-2014-3992 dolibarr vulnerability CVSS: 6.5 11 Jul 2014, 14:55 UTC

Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php.

CVE-2014-3991 dolibarr vulnerability CVSS: 4.3 11 Jul 2014, 14:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu, (5) dol_hide_leftmenu, (6) mainmenu, or (7) leftmenu parameter to index.php; the (8) dol_use_jmobile, (9) dol_optimize_smallscreen, (10) dol_no_mouse_hover, (11) dol_hide_topmenu, or (12) dol_hide_leftmenu parameter to user/index.php; the (13) dol_use_jmobile, (14) dol_optimize_smallscreen, (15) dol_no_mouse_hover, (16) dol_hide_topmenu, or (17) dol_hide_leftmenu parameter to user/logout.php; the (18) email, (19) firstname, (20) job, (21) lastname, or (22) login parameter in an update action in a "User Card" to user/fiche.php; or the (23) modulepart or (24) file parameter to viewimage.php.

CVE-2012-1226 dolibarr vulnerability CVSS: 7.5 21 Feb 2012, 13:31 UTC

Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in the (1) file parameter to document.php or (2) backtopage parameter in a create action to comm/action/fiche.php.

CVE-2012-1225 dolibarr vulnerability CVSS: 7.5 21 Feb 2012, 13:31 UTC

Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to adherents/fiche.php.

CVE-2011-4814 dolibarr vulnerability CVSS: 4.3 14 Dec 2011, 00:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote attackers to inject arbitrary web script or HTML via the PATH_INFO to (1) index.php, (2) admin/boxes.php, (3) comm/clients.php, (4) commande/index.php; and the optioncss parameter to (5) admin/ihm.php and (6) user/home.php.

CVE-2011-4802 dolibarr vulnerability CVSS: 6.5 14 Dec 2011, 00:55 UTC

Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php.

CVE-2011-4329 dolibarr vulnerability CVSS: 4.3 28 Nov 2011, 11:55 UTC

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or (4) admin/user.php.