Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dolibarr Erp\/crm HIGH 8.0
CVE-2019-11201

Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that th…

No fix yet
Fix from $1,950 2019-07-29
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2019-11199

Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each tim…

No fix yet
Fix from $1,600 2019-07-29
Dolibarr Erp\/crm HIGH 8.8
CVE-2019-1010054

Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disa…

No fix yet
Fix from $1,950 2019-07-18
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2019-1010016

Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attac…

No fix yet
Fix from $1,600 2019-07-15
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2017-1000509

Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.

No fix yet
Fix from $1,600 2018-02-09
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2017-17971

The test_sql_and_script_inject function in htdocs/main.inc.php in Dolibarr ERP/CRM 6.0.4 blocks some event attributes but neither onclick nor onscrol…

No fix yet
Fix from $1,600 2017-12-29
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2017-7886

Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.

No fix yet
Fix from $2,300 2017-05-10
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2017-7888

Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.

No fix yet
Fix from $2,300 2017-05-10
Dolibarr Erp\/crm MEDIUM 6.8
CVE-2017-8879

Dolibarr ERP/CRM 4.0.4 allows password changes without supplying the current password, which makes it easier for physically proximate attackers to ob…

No fix yet
Fix from $1,600 2017-05-10
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2017-7887

Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.

No fix yet
Fix from $1,600 2017-05-10
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2014-3992

Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entit…

No fix yet
Fix from $1,600 2014-07-11