Filtered by vendor Dolibarr
Subscribe
Total
138 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2018-25357 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-23 | N/A | 9.8 CRITICAL |
| Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter. | |||||
| CVE-2026-22666 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-14 | N/A | 7.2 HIGH |
| Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluation paths using PHP dynamic callable syntax to bypass validation and achieve arbitrary command execution via eval(). | |||||
| CVE-2024-37821 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-09 | N/A | 8.8 HIGH |
| An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file. | |||||
| CVE-2024-29477 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-09 | N/A | 8.8 HIGH |
| Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input. | |||||
| CVE-2023-38888 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-09 | N/A | 9.6 CRITICAL |
| Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject. | |||||
| CVE-2023-38887 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-09 | N/A | 8.8 HIGH |
| File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions. | |||||
| CVE-2023-38886 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-09 | N/A | 7.2 HIGH |
| An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. | |||||
| CVE-2026-31019 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-05 | N/A | 8.8 HIGH |
| In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code execution with the ability to execute arbitrary operating system commands on the server. | |||||
| CVE-2026-31018 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-05 | N/A | 8.8 HIGH |
| In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation. | |||||
| CVE-2025-56588 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-07-05 | N/A | 8.8 HIGH |
| Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter. | |||||
| CVE-2026-34036 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 6.5 MEDIUM |
| Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access control function restrictedArea(), an authenticated user with no specific privileges can read the contents of arbitrary non-PHP files on the server (such as .env, .htaccess, configuration backups, or logsā¦). At time of publication, there are no publicly available patches. | |||||
| CVE-2026-23500 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.1 CRITICAL |
| Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly into a shell command passed to exec() without sanitization. An authenticated administrator can inject arbitrary OS commands via this constant using command separators, achieving remote code execution as the web server user when any ODT template is generated. This issue has been fixed in version 23.0.0. | |||||
| CVE-2025-67486 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 7.2 HIGH |
| Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is passed to PHP's `eval()` function without adequate sanitization, allowing authenticated administrators to execute arbitrary PHP code on the server. As of time of publication, no patched versions are available. | |||||
| CVE-2024-5315 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.1 CRITICAL |
| Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters viewstatut in /dolibarr/commande/list.php. | |||||
| CVE-2024-5314 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.1 CRITICAL |
| Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php. | |||||
| CVE-2024-55228 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.0 CRITICAL |
| A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-55227 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 9.0 CRITICAL |
| A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter. | |||||
| CVE-2024-31503 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 7.5 HIGH |
| Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover. | |||||
| CVE-2024-23817 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 7.1 HIGH |
| Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifically, I was able to successfully inject a new HTML tag into the returned document and, as a result, was able to comment out some part of the Dolibarr App Home page HTML code. This behavior can be exploited to perform various attacks like Cross-Site Scripting (XSS). To remediate the issue, validate and sanitize all user-supplied input, especially within HTML attributes, to prevent HTML injection attacks; and implement proper output encoding when rendering user-provided data to ensure it is treated as plain text rather than executable HTML. | |||||
| CVE-2023-5842 | 1 Dolibarr | 1 Dolibarr Erp\/crm | 2026-06-17 | N/A | 4.8 MEDIUM |
| Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5. | |||||
