Vulnerabilities (CVE)

Filtered by vendor Dolibarr Subscribe
Total 138 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-13094 1 Dolibarr 1 Dolibarr 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr before 11.0.4 allows XSS.
CVE-2020-12669 1 Dolibarr 1 Dolibarr 2026-06-17 6.5 MEDIUM 8.8 HIGH
core/get_menudiv.php in Dolibarr before 11.0.4 allows remote authenticated attackers to bypass intended access restrictions via a non-alphanumeric menu parameter.
CVE-2020-11825 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 6.8 MEDIUM 8.8 HIGH
In Dolibarr 10.0.6, forms are protected with a CSRF token against CSRF attacks. The problem is any CSRF token in any user's session can be used in another user's session. CSRF tokens should not be valid in this situation.
CVE-2020-11823 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
In Dolibarr 10.0.6, if USER_LOGIN_FAILED is active, there is a stored XSS vulnerability on the admin tools --> audit page. This may lead to stealing of the admin account.
CVE-2019-25710 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 N/A 8.2 HIGH
Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to extract sensitive database information using error-based SQL injection techniques.
CVE-2019-25452 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 N/A 7.5 HIGH
Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious SQL payloads in the elemid parameter to extract sensitive database information using error-based or time-based blind SQL injection techniques.
CVE-2019-25450 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 N/A 7.5 HIGH
Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like actioncode, demand_reason_id, and availability_id in card.php endpoints to extract sensitive database information using boolean-based blind, error-based, and time-based blind techniques.
CVE-2019-19212 1 Dolibarr 1 Dolibarr 2026-06-17 7.5 HIGH 9.8 CRITICAL
Dolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).
CVE-2019-19211 1 Dolibarr 1 Dolibarr 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Dolibarr ERP/CRM before 10.0.3 has an Insufficient Filtering issue that can lead to user/card.php XSS.
CVE-2019-19210 1 Dolibarr 1 Dolibarr 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr ERP/CRM before 10.0.3 allows XSS because uploaded HTML documents are served as text/html despite being renamed to .noexe files.
CVE-2019-19209 1 Dolibarr 1 Dolibarr 2026-06-17 5.0 MEDIUM 7.5 HIGH
Dolibarr ERP/CRM before 10.0.3 allows SQL Injection.
CVE-2019-19206 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr CRM/ERP 10.0.3 allows viewimage.php?file= Stored XSS due to JavaScript execution in an SVG image for a profile picture.
CVE-2019-17578 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Sender email for automatic emails (default value in php.ini: Undefined)" field.
CVE-2019-17577 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the admin/mails.php?action=edit URI via the "Email used for error returns emails (fields 'Errors-To' in emails sent)" field.
CVE-2019-17576 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
An issue was discovered in Dolibarr 10.0.2. It has XSS via the "outgoing email setup" feature in the /admin/mails.php?action=edit URI via the "Send all emails to (instead of real recipients, for test purposes)" field.
CVE-2019-17223 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
There is HTML Injection in the Note field in Dolibarr ERP/CRM 10.0.2 via user/note.php.
CVE-2019-16688 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS in an Email Template section to mails_templates.php. A user with no privileges can inject script to attack the admin. (This stored XSS can affect all types of user privilege from Admin to users with no permissions.)
CVE-2019-16687 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS in a User Profile in a Signature section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.
CVE-2019-16686 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS in a User Note section to note.php. A user with no privileges can inject script to attack the admin.
CVE-2019-16685 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-17 3.5 LOW 5.4 MEDIUM
Dolibarr 9.0.5 has stored XSS vulnerability via a User Group Description section to card.php. A user with the "Create/modify other users, groups and permissions" privilege can inject script and can also achieve privilege escalation.