Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
HIGH 7.5
CVE-2019-25452
Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated …
Dolibarr Erp\/crm
No fix yet
HIGH 7.5
CVE-2019-25450
Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2021-47779
Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject …
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.1
CVE-2024-5315EPSS 35%
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …
Dolibarr Erp\/crm
Mitigation only
CRITICAL 9.1
CVE-2024-5314
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …
Dolibarr Erp\/crm
Mitigation only
MEDIUM 6.1
CVE-2024-23817
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vu…
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2022-30875
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
Dolibarr Erp\/crm
Mitigation only
MEDIUM 5.4
CVE-2022-22293
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.8
CVE-2021-33816
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2021-33618EPSS 79%
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to …
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-13828
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject a…
Dolibarr Erp\/crm
Mitigation only
MEDIUM 5.4
CVE-2020-13239
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct downl…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-13240
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e…
Dolibarr Erp\/crm
No fix yet
HIGH 8.8
CVE-2020-11825
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-11823
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing …
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-9016
Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header.
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.8
CVE-2020-7995
The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts.
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2020-7994
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) labe…
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2020-7996
htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header.
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2019-19206
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
Dolibarr Erp\/crm
Mitigation only
MEDIUM 5.4
CVE-2019-17576
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send a…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2019-17577
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email u…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2019-17578
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender …
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2019-17223
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
Dolibarr Erp\/crm
Mitigation only
MEDIUM 5.4
CVE-2019-16685
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and …
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2019-16686
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2019-16687
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permission…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2019-16688
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (…
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2019-16197
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, l…
Dolibarr Erp\/crm
No fix yet
HIGH 8.8
CVE-2019-11200
Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insuff…
Dolibarr Erp\/crm
No fix yet