Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dolibarr Erp\/crm CRITICAL 9.8
CVE-2022-40871EPSS 33%

Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if …

Fix: after 15.0.3
Fix from $2,300 2022-10-12
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2022-2060

Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.

Fix: 16.0.0+
Fix from $1,600 2022-06-13
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2022-30875

Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.

Mitigation only
Fix from $1,600 2022-06-08
Dolibarr Erp\/crm HIGH 7.5
CVE-2021-37517

An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application al…

Patch available
Fix from $1,950 2022-03-31
Dolibarr Erp\/crm HIGH 8.8
CVE-2021-36625

An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDAT…

Patch available
Fix from $1,950 2022-03-31
Dolibarr Erp\/crm HIGH 8.8
CVE-2022-0819EPSS 41%

Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

Fix: 15.0.1+
Fix from $1,950 2022-03-02
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2022-0731

Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.

Fix: 16.0.0+
Fix from $1,600 2022-02-23
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2022-0224

dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command

Fix: 15.0.0+
Fix from $2,300 2022-01-14
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2022-22293

admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.

No fix yet
Fix from $1,600 2022-01-02
Dolibarr MEDIUM 5.4
CVE-2021-42220

A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies …

Fix: 14.0.3+
Fix from $1,600 2021-12-15
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2021-33816

The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…

No fix yet
Fix from $2,300 2021-11-10
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2021-33618EPSS 79%

Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to …

No fix yet
Fix from $1,600 2021-11-10
Dolibarr HIGH 8.8
CVE-2021-25957

In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset…

Fix: after 13.0.2
Fix from $1,950 2021-08-17
Dolibarr HIGH 7.2
CVE-2021-25956

In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to vali…

Fix: after 13.0.2
Fix from $1,950 2021-08-17
Dolibarr CRITICAL 9.0
CVE-2021-25955

In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application use…

Fix: after 13.0.2
Fix from $2,300 2021-08-15
Dolibarr Erp\/crm HIGH 7.2
CVE-2020-35136EPSS 6%

Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup fu…

Patch available
Fix from $1,950 2020-12-23
Dolibarr HIGH 8.8
CVE-2020-14209EPSS 27%

Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht a…

Fix: 11.0.5+
Fix from $1,950 2020-09-02
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13828

Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject a…

Mitigation only
Fix from $1,600 2020-08-31
Dolibarr MEDIUM 6.5
CVE-2020-14201

Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/documen…

Fix: 11.0.5+
Fix from $1,600 2020-08-21
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2020-14475

A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/no…

Patch available
Fix from $1,600 2020-06-19
Dolibarr HIGH 8.8
CVE-2020-14443

A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands…

Fix: after 11.0.3
Fix from $1,950 2020-06-18
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13239

The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct downl…

No fix yet
Fix from $1,600 2020-05-20
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-13240

The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e…

No fix yet
Fix from $1,600 2020-05-20
Dolibarr MEDIUM 5.4
CVE-2020-13094

Dolibarr before 11.0.4 allows XSS.

Fix: 11.0.4+
Fix from $1,600 2020-05-18
Dolibarr HIGH 8.8
CVE-2020-12669

core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric me…

Fix: 11.0.4+
Fix from $1,950 2020-05-06
Dolibarr Erp\/crm HIGH 8.8
CVE-2020-11825

In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an…

No fix yet
Fix from $1,950 2020-04-16
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2020-11823

In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing …

No fix yet
Fix from $1,600 2020-04-16
Dolibarr CRITICAL 9.8
CVE-2019-19212

Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).

Fix: after 10.0.3
Fix from $2,300 2020-03-16
Dolibarr HIGH 7.5
CVE-2019-19209

Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.

Fix: 10.0.3+
Fix from $1,950 2020-03-16
Dolibarr MEDIUM 6.1
CVE-2019-19211

Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.

Fix: 10.0.4+
Fix from $1,600 2020-03-16