Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dolibarr Erp\/crm HIGH 7.5
CVE-2019-25452

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated …

No fix yet
Fix from $1,950 2026-02-22
Dolibarr Erp\/crm HIGH 7.5
CVE-2019-25450

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin…

No fix yet
Fix from $1,950 2026-02-22
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2021-47779

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject …

No fix yet
Fix from $1,600 2026-01-16
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2024-5315EPSS 35%

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …

Mitigation only
Fix from $2,300 2024-05-24
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2024-5314

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …

Mitigation only
Fix from $2,300 2024-05-24
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2024-23817

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vu…

No fix yet
Fix from $1,600 2024-01-25
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2022-30875

Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

Mitigation only
Fix from $1,600 2022-06-08
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2022-22293

admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

No fix yet
Fix from $1,600 2022-01-02
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2021-33816

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…

No fix yet
Fix from $2,300 2021-11-10
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2021-33618EPSS 79%

Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to …

No fix yet
Fix from $1,600 2021-11-10
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13828

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject a…

Mitigation only
Fix from $1,600 2020-08-31
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13239

The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct downl…

No fix yet
Fix from $1,600 2020-05-20
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13240

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e…

No fix yet
Fix from $1,600 2020-05-20
Dolibarr Erp\/crm HIGH 8.8
CVE-2020-11825

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an…

No fix yet
Fix from $1,950 2020-04-16
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-11823

In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing …

No fix yet
Fix from $1,600 2020-04-16
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-9016

Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.

No fix yet
Fix from $1,600 2020-02-16
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2020-7995

The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.

No fix yet
Fix from $2,300 2020-01-26
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2020-7994

Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) labe…

No fix yet
Fix from $1,600 2020-01-26
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2020-7996

htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.

No fix yet
Fix from $1,600 2020-01-26
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-19206

Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.

Mitigation only
Fix from $1,600 2019-11-26
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-17576

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send a…

No fix yet
Fix from $1,600 2019-10-16
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-17577

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email u…

No fix yet
Fix from $1,600 2019-10-16
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-17578

An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender …

No fix yet
Fix from $1,600 2019-10-16
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2019-17223

There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.

Mitigation only
Fix from $1,600 2019-10-15
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-16685

Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and …

No fix yet
Fix from $1,600 2019-09-27
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-16686

Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.

No fix yet
Fix from $1,600 2019-09-27
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-16687

Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permission…

No fix yet
Fix from $1,600 2019-09-27
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-16688

Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (…

No fix yet
Fix from $1,600 2019-09-27
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2019-16197

In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, l…

No fix yet
Fix from $1,600 2019-09-16
Dolibarr Erp\/crm HIGH 8.8
CVE-2019-11200

Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insuff…

No fix yet
Fix from $1,950 2019-07-29