← Back

Dolibarr

dolibarr

138 CVEs • 2 products

Products (2)

Click to collapse
Toggle
Dolibarr
dolibarr

CVEs (138)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dolibarr
1Dolibarr
Jun 17, 2026
May 6, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Apr 16, 2020
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation...Show more
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Apr 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
1Dolibarr
1Dolibarr
Jun 17, 2026
Mar 16, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
1Dolibarr
1Dolibarr
Jun 17, 2026
Mar 16, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
1Dolibarr
1Dolibarr
Jun 17, 2026
Mar 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
1Dolibarr
1Dolibarr
Jun 17, 2026
Mar 16, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Feb 16, 2020
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jan 26, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jan 26, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jan 26, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) n...Show more
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the /htdocs/admin/const.php?mainmenu=home page; the (3) note[note] parameter to the /htdocs/admin/dict.php?id=10 page; the (4) zip[MAIN_INFO_SOCIETE_ZIP] or email[mail] parameter to the /htdocs/admin/company.php page; the (5) url[defaulturl], field[defaultkey], or value[defaultvalue] parameter to the /htdocs/admin/defaultvalues.php page; the (6) key[transkey] or key[transvalue] parameter to the /htdocs/admin/translation.php page; or the (7) [main_motd] or [main_home] parameter to the /htdocs/admin/ihm.php page.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Nov 26, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary commands.
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Nov 20, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php.
1Dolibarr
1Dolibarr Erp/crm
Nov 21, 2024
Nov 20, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Oct 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field...Show more
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Oct 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field...Show more
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Oct 16, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Oct 15, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Sep 27, 2019
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to us...Show more
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)Show less