Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2019-19210 Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files. Dolibarr 10.0.3+ Fix from $1,6002020-03-16 MEDIUM 5.4 CVE-2020-9016 Dolibarr 11.0 allows XSS via the joinfiles, topic, or code parameter, or the HTTP Referer header. Dolibarr Erp\/crm No fix yet Fix from $1,6002020-02-16 CRITICAL 9.8 CVE-2020-7995 The htdocs/index.php?mainmenu=home login page in Dolibarr 10.0.6 allows an unlimited rate of failed authentication attempts. Dolibarr Erp\/crm No fix yet Fix from $2,3002020-01-26 MEDIUM 6.1 CVE-2020-7994 Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote attackers to inject arbitrary web script or HTML via the (1) labe… Dolibarr Erp\/crm No fix yet Fix from $1,6002020-01-26 MEDIUM 6.1 CVE-2020-7996 htdocs/user/passwordforgotten.php in Dolibarr 10.0.6 allows XSS via the Referer HTTP header. Dolibarr Erp\/crm No fix yet Fix from $1,6002020-01-26 MEDIUM 5.4 CVE-2019-19206 Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture. Dolibarr Erp\/crm Mitigation only Fix from $1,6002019-11-26 CRITICAL 9.8 CVE-2013-2093EPSS 5% Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote attackers to execute arbitrary … Dolibarr Erp\/crm Patch available Fix from $2,3002019-11-20 MEDIUM 6.1 CVE-2013-2092 Cross-site Scripting (XSS) in Dolibarr ERP/CRM 3.3.1 allows remote attackers to inject arbitrary web script or HTML in functions.lib.php. Dolibarr Erp\/crm Patch available Fix from $1,6002019-11-20 CRITICAL 9.8 CVE-2013-2091 SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php. Dolibarr Erp\/crm Patch available Fix from $2,3002019-11-20 MEDIUM 5.4 CVE-2019-17576 An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send a… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-10-16 MEDIUM 5.4 CVE-2019-17577 An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email u… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-10-16 MEDIUM 5.4 CVE-2019-17578 An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender … Dolibarr Erp\/crm No fix yet Fix from $1,6002019-10-16 MEDIUM 6.1 CVE-2019-17223 There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php. Dolibarr Erp\/crm Mitigation only Fix from $1,6002019-10-15 MEDIUM 5.4 CVE-2019-16685 Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and … Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 5.4 CVE-2019-16686 Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin. Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 5.4 CVE-2019-16687 Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permission… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 5.4 CVE-2019-16688 Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-27 MEDIUM 6.1 CVE-2019-16197 In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document as plain text between tags, l… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-09-16 HIGH 8.0 CVE-2019-15062 An issue was discovered in Dolibarr 11.0.0-alpha. A user can store an IFRAME element (containing a user/card.php CSRF request) in his Linked Files se… Dolibarr Erp\/crm Patch available Fix from $1,9502019-08-14 HIGH 8.8 CVE-2019-11200 Dolibarr ERP/CRM 9.0.1 provides a web-based functionality that backs up the database content to a dump file. However, the application performs insuff… Dolibarr Erp\/crm No fix yet Fix from $1,9502019-07-29 HIGH 8.0 CVE-2019-11201 Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that th… Dolibarr Erp\/crm No fix yet Fix from $1,9502019-07-29 MEDIUM 5.4 CVE-2019-11199 Dolibarr ERP/CRM 9.0.1 was affected by stored XSS within uploaded files. These vulnerabilities allowed the execution of a JavaScript payload each tim… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-07-29 HIGH 8.8 CVE-2019-1010054 Dolibarr 7.0.0 is affected by: Cross Site Request Forgery (CSRF). The impact is: allow malitious html to change user password, disable users and disa… Dolibarr Erp\/crm No fix yet Fix from $1,9502019-07-18 MEDIUM 6.1 CVE-2019-1010016 Dolibarr 6.0.4 is affected by: Cross Site Scripting (XSS). The impact is: Cookie stealing. The component is: htdocs/product/stats/card.php. The attac… Dolibarr Erp\/crm No fix yet Fix from $1,6002019-07-15 CRITICAL 9.8 CVE-2018-16809 An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer paramete… Dolibarr after 7.0.0 Fix from $2,3002019-03-07 MEDIUM 6.1 CVE-2018-16808 An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments param… Dolibarr after 7.0.0 Fix from $1,6002019-03-07 HIGH 8.8 CVE-2018-19994 An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL c… Dolibarr Erp\/crm Patch available Fix from $1,9502019-01-03 HIGH 8.8 CVE-2018-19998 SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the em… Dolibarr Erp\/crm Patch available Fix from $1,9502019-01-03 MEDIUM 6.1 CVE-2018-19993 A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transph… Dolibarr Erp\/crm Patch available Fix from $1,6002019-01-03 MEDIUM 5.4 CVE-2018-19995 A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the … Dolibarr Erp\/crm Patch available Fix from $1,6002019-01-03