Vulnerability index

Browse CVEs

128 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Dolibarr Erp\/crm CRITICAL 9.8
CVE-2018-25357

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PH…

Fix: after 7.0.3
Fix from $2,300 2026-05-23
Dolibarr Erp\/crm HIGH 7.2
CVE-2025-67486

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains a…

Fix: after 22.0.2
Fix from $1,950 2026-05-08
Dolibarr Erp\/crm HIGH 8.8
CVE-2026-31018

In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input…

Fix: after 22.0.4
Fix from $1,950 2026-04-21
Dolibarr Erp\/crm HIGH 8.8
CVE-2026-31019

In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions rela…

Fix: after 22.0.4
Fix from $1,950 2026-04-21
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2026-23500

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT …

Fix: 23.0.0+
Fix from $2,300 2026-04-17
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2019-25710

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute…

Fix: after 8.0.4
Fix from $2,300 2026-04-12
Dolibarr Erp\/crm HIGH 7.2
CVE-2026-22666EPSS 16%

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails…

Fix: 23.0.2+
Fix from $1,950 2026-04-07
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2026-34036

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is…

Fix: after 22.0.4
Fix from $1,600 2026-03-31
Dolibarr Erp\/crm HIGH 7.5
CVE-2019-25452

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated …

No fix yet
Fix from $1,950 2026-02-22
Dolibarr Erp\/crm HIGH 7.5
CVE-2019-25450

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injectin…

No fix yet
Fix from $1,950 2026-02-22
Dolibarr Erp\/crm MEDIUM 5.4
CVE-2021-47779

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject …

No fix yet
Fix from $1,600 2026-01-16
Dolibarr Erp\/crm HIGH 8.8
CVE-2025-56588

Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed f…

Patch available
Fix from $1,950 2025-10-01
Dolibarr Erp\/crm CRITICAL 9.0
CVE-2024-55227

A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or …

Patch available
Fix from $2,300 2025-01-27
Dolibarr Erp\/crm CRITICAL 9.0
CVE-2024-55228

A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl v…

Patch available
Fix from $2,300 2025-01-27
Dolibarr Erp\/crm HIGH 8.8
CVE-2024-37821

An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code v…

Fix: 19.0.2+
Fix from $1,950 2024-06-18
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2024-5315EPSS 35%

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …

Mitigation only
Fix from $2,300 2024-05-24
Dolibarr Erp\/crm CRITICAL 9.1
CVE-2024-5314

Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send …

Mitigation only
Fix from $2,300 2024-05-24
Dolibarr Erp\/crm HIGH 7.5
CVE-2024-31503

Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CS…

Fix: 19.0.1+
Fix from $1,950 2024-04-17
Dolibarr Erp\/crm HIGH 8.8
CVE-2024-29477

Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to e…

Fix: 19.0.1+
Fix from $1,950 2024-04-03
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2024-23817

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vu…

No fix yet
Fix from $1,600 2024-01-25
Dolibarr Erp\/crm MEDIUM 6.5
CVE-2023-4198

Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

Fix: after 17.0.3
Fix from $1,600 2023-11-01
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-4197EPSS 33%

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing a…

Fix: after 18.0.1
Fix from $1,950 2023-11-01
Dolibarr Erp\/crm MEDIUM 6.1
CVE-2023-5323

Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.

Fix: 18.0+
Fix from $1,600 2023-10-01
Dolibarr Erp\/crm CRITICAL 9.6
CVE-2023-38888

Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbit…

Fix: after 17.0.1
Fix from $2,300 2023-09-20
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-38887

File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information…

Fix: after 17.0.1
Fix from $1,950 2023-09-20
Dolibarr Erp\/crm HIGH 7.2
CVE-2023-38886EPSS 29%

An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

Fix: after 17.0.1
Fix from $1,950 2023-09-20
Dolibarr Erp\/crm HIGH 7.5
CVE-2023-33568EPSS 15%

An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospe…

Fix: 16.0.5+
Fix from $1,950 2023-06-13
Dolibarr Erp\/crm HIGH 8.8
CVE-2023-30253EPSS 79%

Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.

Fix: 17.0.1+
Fix from $1,950 2023-05-29
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2022-4093

SQL injection attacks can result in unauthorized access to sensitive data, such as passwords, credit card details, or personal user information. Many…

Patch available
Fix from $2,300 2022-11-21
Dolibarr Erp\/crm CRITICAL 9.8
CVE-2022-43138

Dolibarr Open Source ERP & CRM for Business before v14.0.1 allows attackers to escalate privileges via a crafted API.

Fix: 14.0.1+
Fix from $2,300 2022-11-17