Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
CRITICAL 9.8
CVE-2022-40871EPSS 33%
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if …
Dolibarr Erp\/crm
after 15.0.3
MEDIUM 5.4
CVE-2022-2060
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.
Dolibarr Erp\/crm
16.0.0+
MEDIUM 6.1
CVE-2022-30875
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
Dolibarr Erp\/crm
Mitigation only
HIGH 7.5
CVE-2021-37517
An Access Control vulnerability exists in Dolibarr ERP/CRM 13.0.2, fixed version is 14.0.0,in the forgot-password function becuase the application al…
Dolibarr Erp\/crm
Patch available
HIGH 8.8
CVE-2021-36625
An SQL Injection vulnerability exists in Dolibarr ERP/CRM 13.0.2 (fixed version is 14.0.0) via a POST request to the country_id parameter in an UPDAT…
Dolibarr Erp\/crm
Patch available
HIGH 8.8
CVE-2022-0819EPSS 41%
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
Dolibarr Erp\/crm
15.0.1+
MEDIUM 6.5
CVE-2022-0731
Improper Access Control (IDOR) in GitHub repository dolibarr/dolibarr prior to 16.0.
Dolibarr Erp\/crm
16.0.0+
CRITICAL 9.8
CVE-2022-0224
dolibarr is vulnerable to Improper Neutralization of Special Elements used in an SQL Command
Dolibarr Erp\/crm
15.0.0+
MEDIUM 5.4
CVE-2022-22293
admin/limits.php in Dolibarr 7.0.2 allows HTML injection, as demonstrated by the MAIN_MAX_DECIMALS_TOT parameter.
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2021-42220
A Cross Site Scripting (XSS) vulnerability exists in Dolibarr before 14.0.3 via the ticket creation flow. Exploitation requires that an admin copies …
Dolibarr
14.0.3+
CRITICAL 9.8
CVE-2021-33816
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, a…
Dolibarr Erp\/crm
No fix yet
MEDIUM 6.1
CVE-2021-33618EPSS 79%
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to …
Dolibarr Erp\/crm
No fix yet
HIGH 8.8
CVE-2021-25957
In “Dolibarr” application, v2.8.1 to v13.0.2 are vulnerable to account takeover via password reset functionality. A low privileged attacker can reset…
Dolibarr
after 13.0.2
HIGH 7.2
CVE-2021-25956
In “Dolibarr” application, v3.3.beta1_20121221 to v13.0.2 have “Modify” access for admin level users to change other user’s details but fails to vali…
Dolibarr
after 13.0.2
CRITICAL 9.0
CVE-2021-25955
In “Dolibarr ERP CRM”, WYSIWYG Editor module, v2.8.1 to v13.0.2 are affected by a stored XSS vulnerability that allows low privileged application use…
Dolibarr
after 13.0.2
HIGH 7.2
CVE-2020-35136EPSS 6%
Dolibarr 12.0.3 is vulnerable to authenticated Remote Code Execution. An attacker who has the access the admin dashboard can manipulate the backup fu…
Dolibarr Erp\/crm
Patch available
HIGH 8.8
CVE-2020-14209EPSS 27%
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht a…
Dolibarr
11.0.5+
MEDIUM 5.4
CVE-2020-13828
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated attackers to inject a…
Dolibarr Erp\/crm
Mitigation only
MEDIUM 6.5
CVE-2020-14201
Dolibarr CRM before 11.0.5 allows privilege escalation. This could allow remote authenticated attackers to upload arbitrary files via societe/documen…
Dolibarr
11.0.5+
MEDIUM 6.1
CVE-2020-14475
A reflected cross-site scripting (XSS) vulnerability in Dolibarr 11.0.3 allows remote attackers to inject arbitrary web script or HTML into public/no…
Dolibarr Erp\/crm
Patch available
HIGH 8.8
CVE-2020-14443
A SQL injection vulnerability in accountancy/customer/card.php in Dolibarr 11.0.3 allows remote authenticated users to execute arbitrary SQL commands…
Dolibarr
after 11.0.3
MEDIUM 5.4
CVE-2020-13239
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct downl…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-13240
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file e…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-13094
Dolibarr before 11.0.4 allows XSS.
Dolibarr
11.0.4+
HIGH 8.8
CVE-2020-12669
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric me…
Dolibarr
11.0.4+
HIGH 8.8
CVE-2020-11825
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in an…
Dolibarr Erp\/crm
No fix yet
MEDIUM 5.4
CVE-2020-11823
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing …
Dolibarr Erp\/crm
No fix yet
CRITICAL 9.8
CVE-2019-19212
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
Dolibarr
after 10.0.3
HIGH 7.5
CVE-2019-19209
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
Dolibarr
10.0.3+
MEDIUM 6.1
CVE-2019-19211
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
Dolibarr
10.0.4+