Vulnerability index

Browse CVEs

41 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2019-25452 Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated … Dolibarr Erp\/crm No fix yet Fix from $1,9502026-02-22 HIGH 7.5 CVE-2019-25450 Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin… Dolibarr Erp\/crm No fix yet Fix from $1,9502026-02-22 MEDIUM 5.4 CVE-2021-47779 Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject … Dolibarr Erp\/crm No fix yet Fix from $1,6002026-01-16 CRITICAL 9.1 CVE-2024-5315EPSS 35% Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send … Dolibarr Erp\/crm Mitigation only Fix from $2,3002024-05-24 CRITICAL 9.1 CVE-2024-5314 Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send … Dolibarr Erp\/crm Mitigation only Fix from $2,3002024-05-24 MEDIUM 6.1 CVE-2024-23817 Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vu… Dolibarr Erp\/crm No fix yet Fix from $1,6002024-01-25 MEDIUM 6.1 CVE-2022-30875 Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. Dolibarr Erp\/crm Mitigation only Fix from $1,6002022-06-08 MEDIUM 5.4 CVE-2022-22293 admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter. Dolibarr Erp\/crm No fix yet Fix from $1,6002022-01-02 CRITICAL 9.8 CVE-2021-33816 The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a… Dolibarr Erp\/crm No fix yet Fix from $2,3002021-11-10 MEDIUM 6.1 CVE-2021-33618EPSS 79% Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to … Dolibarr Erp\/crm No fix yet Fix from $1,6002021-11-10 MEDIUM 5.4 CVE-2020-13828 Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject a… Dolibarr Erp\/crm Mitigation only Fix from $1,6002020-08-31 MEDIUM 5.4 CVE-2020-13239 The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct downl… Dolibarr Erp\/crm No fix yet Fix from $1,6002020-05-20 MEDIUM 5.4 CVE-2020-13240 The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e… Dolibarr Erp\/crm No fix yet Fix from $1,6002020-05-20 HIGH 8.8 CVE-2020-11825 In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an… Dolibarr Erp\/crm No fix yet Fix from $1,9502020-04-16 MEDIUM 5.4 CVE-2020-11823 In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing … Dolibarr Erp\/crm No fix yet Fix from $1,6002020-04-16 MEDIUM 5.4 CVE-2020-9016 Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header. Dolibarr Erp\/crm No fix yet Fix from $1,6002020-02-16 CRITICAL 9.8 CVE-2020-7995 The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts. Dolibarr Erp\/crm No fix yet Fix from $2,3002020-01-26 MEDIUM 6.1 CVE-2020-7994 Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) labe… Dolibarr Erp\/crm No fix yet Fix from $1,6002020-01-26 MEDIUM 6.1 CVE-2020-7996 htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header. Dolibarr Erp\/crm No fix yet Fix from $1,6002020-01-26 MEDIUM 5.4 CVE-2019-19206 Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture. Dolibarr Erp\/crm Mitigation only Fix from $1,6002019-11-26 MEDIUM 5.4 CVE-2019-17576 An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send a… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-10-16 MEDIUM 5.4 CVE-2019-17577 An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email u… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-10-16 MEDIUM 5.4 CVE-2019-17578 An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender … Dolibarr Erp\/crm No fix yet Fix from $1,6002019-10-16 MEDIUM 6.1 CVE-2019-17223 There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. Dolibarr Erp\/crm Mitigation only Fix from $1,6002019-10-15 MEDIUM 5.4 CVE-2019-16685 Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and … Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 5.4 CVE-2019-16686 Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin. Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 5.4 CVE-2019-16687 Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permission… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 5.4 CVE-2019-16688 Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 6.1 CVE-2019-16197 In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, l… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-16 HIGH 8.8 CVE-2019-11200 Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insuff… Dolibarr Erp\/crm No fix yet Fix from $1,9502019-07-29