Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2022-40871EPSS 33% Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if … Dolibarr Erp\/crm after 15.0.3 Fix from $2,3002022-10-12 MEDIUM 5.4 CVE-2022-2060 Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0. Dolibarr Erp\/crm 16.0.0+ Fix from $1,6002022-06-13 MEDIUM 6.1 CVE-2022-30875 Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page. Dolibarr Erp\/crm Mitigation only Fix from $1,6002022-06-08 HIGH 7.5 CVE-2021-37517 An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application al… Dolibarr Erp\/crm Patch available Fix from $1,9502022-03-31 HIGH 8.8 CVE-2021-36625 An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDAT… Dolibarr Erp\/crm Patch available Fix from $1,9502022-03-31 HIGH 8.8 CVE-2022-0819EPSS 41% Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1. Dolibarr Erp\/crm 15.0.1+ Fix from $1,9502022-03-02 MEDIUM 6.5 CVE-2022-0731 Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0. Dolibarr Erp\/crm 16.0.0+ Fix from $1,6002022-02-23 CRITICAL 9.8 CVE-2022-0224 dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command Dolibarr Erp\/crm 15.0.0+ Fix from $2,3002022-01-14 MEDIUM 5.4 CVE-2022-22293 admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter. Dolibarr Erp\/crm No fix yet Fix from $1,6002022-01-02 MEDIUM 5.4 CVE-2021-42220 A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies … Dolibarr 14.0.3+ Fix from $1,6002021-12-15 CRITICAL 9.8 CVE-2021-33816 The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a… Dolibarr Erp\/crm No fix yet Fix from $2,3002021-11-10 MEDIUM 6.1 CVE-2021-33618EPSS 79% Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to … Dolibarr Erp\/crm No fix yet Fix from $1,6002021-11-10 HIGH 8.8 CVE-2021-25957 In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset… Dolibarr after 13.0.2 Fix from $1,9502021-08-17 HIGH 7.2 CVE-2021-25956 In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to vali… Dolibarr after 13.0.2 Fix from $1,9502021-08-17 CRITICAL 9.0 CVE-2021-25955 In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application use… Dolibarr after 13.0.2 Fix from $2,3002021-08-15 HIGH 7.2 CVE-2020-35136EPSS 6% Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup fu… Dolibarr Erp\/crm Patch available Fix from $1,9502020-12-23 HIGH 8.8 CVE-2020-14209EPSS 27% Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht a… Dolibarr 11.0.5+ Fix from $1,9502020-09-02 MEDIUM 5.4 CVE-2020-13828 Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject a… Dolibarr Erp\/crm Mitigation only Fix from $1,6002020-08-31 MEDIUM 6.5 CVE-2020-14201 Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/documen… Dolibarr 11.0.5+ Fix from $1,6002020-08-21 MEDIUM 6.1 CVE-2020-14475 A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/no… Dolibarr Erp\/crm Patch available Fix from $1,6002020-06-19 HIGH 8.8 CVE-2020-14443 A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands… Dolibarr after 11.0.3 Fix from $1,9502020-06-18 MEDIUM 5.4 CVE-2020-13239 The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct downl… Dolibarr Erp\/crm No fix yet Fix from $1,6002020-05-20 MEDIUM 5.4 CVE-2020-13240 The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e… Dolibarr Erp\/crm No fix yet Fix from $1,6002020-05-20 MEDIUM 5.4 CVE-2020-13094 Dolibarr before 11.0.4 allows XSS. Dolibarr 11.0.4+ Fix from $1,6002020-05-18 HIGH 8.8 CVE-2020-12669 core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric me… Dolibarr 11.0.4+ Fix from $1,9502020-05-06 HIGH 8.8 CVE-2020-11825 In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an… Dolibarr Erp\/crm No fix yet Fix from $1,9502020-04-16 MEDIUM 5.4 CVE-2020-11823 In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing … Dolibarr Erp\/crm No fix yet Fix from $1,6002020-04-16 CRITICAL 9.8 CVE-2019-19212 Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen). Dolibarr after 10.0.3 Fix from $2,3002020-03-16 HIGH 7.5 CVE-2019-19209 Dolibarr ERP/CRM before 10.0.3 allows SQL Injection. Dolibarr 10.0.3+ Fix from $1,9502020-03-16 MEDIUM 6.1 CVE-2019-19211 Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS. Dolibarr 10.0.4+ Fix from $1,6002020-03-16