Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2018-25357
Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH…
Dolibarr Erp\/crm
after 7.0.3
HIGH 7.2
CVE-2025-67486
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains a…
Dolibarr Erp\/crm
after 22.0.2
HIGH 8.8
CVE-2026-31018
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input…
Dolibarr Erp\/crm
after 22.0.4
HIGH 8.8
CVE-2026-31019
In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions rela…
Dolibarr Erp\/crm
after 22.0.4
CRITICAL 9.1
CVE-2026-23500
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT …
Dolibarr Erp\/crm
23.0.0+
CRITICAL 9.1
CVE-2019-25710
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute…
Dolibarr Erp\/crm
after 8.0.4
HIGH 7.2
CVE-2026-22666EPSS 16%
Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails…
Dolibarr Erp\/crm
23.0.2+
MEDIUM 6.5
CVE-2026-34036
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is…
Dolibarr Erp\/crm
after 22.0.4
HIGH 7.5
CVE-2019-25452
Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated …
Dolibarr Erp\/crm
No fix yet
HIGH 7.5
CVE-2019-25450
Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2021-47779
Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject …
Dolibarr Erp\/crm
No fix yet
HIGH 8.8
CVE-2025-56588
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed f…
Dolibarr Erp\/crm
Patch available
CRITICAL 9.0
CVE-2024-55227
A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or …
Dolibarr Erp\/crm
Patch available
CRITICAL 9.0
CVE-2024-55228
A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl v…
Dolibarr Erp\/crm
Patch available
HIGH 8.8
CVE-2024-37821
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code v…
Dolibarr Erp\/crm
19.0.2+
CRITICAL 9.1
CVE-2024-5315EPSS 35%
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …
Dolibarr Erp\/crm
Mitigation only
CRITICAL 9.1
CVE-2024-5314
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …
Dolibarr Erp\/crm
Mitigation only
HIGH 7.5
CVE-2024-31503
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CS…
Dolibarr Erp\/crm
19.0.1+
HIGH 8.8
CVE-2024-29477
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to e…
Dolibarr Erp\/crm
19.0.1+
MEDIUM 6.1
CVE-2024-23817
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vu…
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.5
CVE-2023-4198
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
Dolibarr Erp\/crm
after 17.0.3
HIGH 8.8
CVE-2023-4197EPSS 33%
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a…
Dolibarr Erp\/crm
after 18.0.1
MEDIUM 6.1
CVE-2023-5323
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
Dolibarr Erp\/crm
18.0+
CRITICAL 9.6
CVE-2023-38888
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbit…
Dolibarr Erp\/crm
after 17.0.1
HIGH 8.8
CVE-2023-38887
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information…
Dolibarr Erp\/crm
after 17.0.1
HIGH 7.2
CVE-2023-38886EPSS 29%
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
Dolibarr Erp\/crm
after 17.0.1
HIGH 7.5
CVE-2023-33568EPSS 15%
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospe…
Dolibarr Erp\/crm
16.0.5+
HIGH 8.8
CVE-2023-30253EPSS 79%
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
Dolibarr Erp\/crm
17.0.1+
CRITICAL 9.8
CVE-2022-4093
SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many…
Dolibarr Erp\/crm
Patch available
CRITICAL 9.8
CVE-2022-43138
Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.
Dolibarr Erp\/crm
14.0.1+