Dolibarr vulnerabilities
105 known vulnerabilities affecting dolibarr/dolibarr.
Total CVEs
105
CISA KEV
0
Public exploits
8
Exploited in wild
0
Severity breakdown
CRITICAL25HIGH33MEDIUM47
Vulnerabilities
Page 1 of 6
CVE-2026-34036MEDIUMCVSS 6.5≤ 22.0.42026-03-31
CVE-2026-34036 [MEDIUM] CWE-98 CVE-2026-34036: Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) softwar
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22.0.4 and prior, there is a Local File Inclusion (LFI) vulnerability in the core AJAX endpoint /core/ajax/selectobject.php. By manipulating the objectdesc parameter and exploiting a fail-open logic flaw in the core access contro
cvelistv5ghsanvdosv
CVE-2020-36966MEDIUMCVSS 5.1≤ 11.0.32026-01-30
CVE-2020-36966 [MEDIUM] CWE-79 CVE-2020-36966: Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization set
Dolibarr 11.0.3 contains a persistent cross-site scripting vulnerability in LDAP synchronization settings that allows attackers to inject malicious scripts through multiple parameters. Attackers can exploit the host, slave, and port parameters in /dolibarr/admin/ldap.php to execute arbitrary JavaScript and potentially steal user cookie information.
cvelistv5nvd
CVE-2025-56588HIGH≥ 0, < 21.0.32025-10-01
CVE-2025-56588 [HIGH] CWE-94 Dolibarr vulnerable to RCE via the computed field parameter
Dolibarr vulnerable to RCE via the computed field parameter
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
ghsaosv
CVE-2021-3991MEDIUM≥ 0, < 15.0.02024-11-15
CVE-2021-3991 [MEDIUM] CWE-285 Improper Authorization in dolibarr/dolibarr
Improper Authorization in dolibarr/dolibarr
An Improper Authorization vulnerability exists in Dolibarr versions prior to version 15.0.0. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intended permission restrictions.
ghsaosv
CVE-2024-40137HIGH≥ 0, < 19.0.22024-07-24
CVE-2024-40137 [HIGH] CWE-74 Dolibarr ERP CRM vulnerable to remote code execution (RCE)
Dolibarr ERP CRM vulnerable to remote code execution (RCE)
Dolibarr ERP CRM before 19.0.2 was discovered to contain a remote code execution (RCE) vulnerability via the Computed field parameter under the Users Module Setup function.
ghsaosv
CVE-2024-37821HIGH≥ 0, < 19.0.22024-06-18
CVE-2024-37821 [HIGH] CWE-434 Dolibarr arbitrary file upload vulnerability
Dolibarr arbitrary file upload vulnerability
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
ghsaosv
CVE-2024-34051MEDIUM≥ 0, < 19.0.22024-06-03
CVE-2024-34051 [MEDIUM] CWE-79 Reflected Cross-Site Scripting (XSS) in Dolibarr
Reflected Cross-Site Scripting (XSS) in Dolibarr
A Reflected Cross-site scripting (XSS) vulnerability located in htdocs/compta/paiement/card.php of Dolibarr before 19.0.2 allows remote attackers to inject arbitrary web script or HTML via a crafted payload injected into the facid parameter.
ghsaosv
CVE-2024-5314CRITICAL≥ 0, ≤ 9.0.12024-05-24
CVE-2024-5314 [CRITICAL] CWE-89 Dolibarr vulnerable to SQL Injection
Dolibarr vulnerable to SQL Injection
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters sortorder y sortfield in /dolibarr/admin/dict.php.
ghsaosv
CVE-2024-5315CRITICALPoC≥ 0, ≤ 9.0.12024-05-24
CVE-2024-5315 [CRITICAL] CWE-89 Dolibarr vulnerable to SQL Injection
Dolibarr vulnerable to SQL Injection
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query to the system and retrieve all the information stored in the database through the parameters in /dolibarr/commande/list.php.
ghsaosv
CVE-2024-31503HIGH≥ 0, ≤ 19.0.02024-04-17
CVE-2024-31503 [HIGH] CWE-284 Dolibarr vulnerable to Cross-Site Request Forgery
Dolibarr vulnerable to Cross-Site Request Forgery
Incorrect access control in Dolibarr ERP CRM versions 19.0.0 and before, allows authenticated attackers to steal victim users' session cookies and CSRF protection tokens via user interaction with a crafted web page, leading to account takeover.
ghsaosv
CVE-2024-29477MEDIUM≥ 0, ≤ 19.0.02024-04-03
CVE-2024-29477 [MEDIUM] CWE-94 Dolibarr ERP CRM Code Injection vulnerability during installation
Dolibarr ERP CRM Code Injection vulnerability during installation
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.
ghsaosv
CVE-2024-23817MEDIUMCVSS 6.1v= 18.0.42024-01-25
CVE-2024-23817 [MEDIUM] CWE-79 CVE-2024-23817: Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) softwar
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to inject arbitrary HTML tags and manipulate the rendered content in the application's response. Specifical
cvelistv5ghsanvdosv
CVE-2023-4197HIGH≥ 0, < 18.0.22023-11-01
CVE-2023-4197 [HIGH] CWE-20 Dolibarr Improper Input Validation vulnerability
Dolibarr Improper Input Validation vulnerability
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
ghsaosv
CVE-2023-4198MEDIUM≥ 0, < 18.0.02023-11-01
CVE-2023-4198 [MEDIUM] CWE-862 Dolibarr Improper Input Validation vulnerability
Dolibarr Improper Input Validation vulnerability
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
ghsaosv
CVE-2023-5842MEDIUM≥ 0, < 16.0.52023-10-30
CVE-2023-5842 [MEDIUM] CWE-79 Cross-site Scripting (XSS) in dolibarr/dolibarr
Cross-site Scripting (XSS) in dolibarr/dolibarr
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
ghsaosv
CVE-2023-5323MEDIUM≥ 0, < 18.0.02023-10-01
CVE-2023-5323 [MEDIUM] CWE-79 Dolibarr Cross-site Scripting vulnerability
Dolibarr Cross-site Scripting vulnerability
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.0.
ghsaosv
CVE-2023-38888CRITICAL≥ 0, < 17.0.12023-09-20
CVE-2023-38888 [CRITICAL] CWE-79 Cross Site Scripting vulnerability in Dolibarr ERP CRM
Cross Site Scripting vulnerability in Dolibarr ERP CRM
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScriptInject.
ghsaosv
CVE-2023-38887HIGH≥ 0, < 17.0.12023-09-20
CVE-2023-38887 [HIGH] CWE-434 File Upload vulnerability in Dolibarr ERP CRM
File Upload vulnerability in Dolibarr ERP CRM
File Upload vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to execute arbitrary code and obtain sensitive information via the extension filtering and renaming functions.
ghsaosv
CVE-2023-38886HIGH≥ 0, < 17.0.12023-09-20
CVE-2023-38886 [HIGH] CWE-78 Dolibarr allows a remote privileged attacker to execute arbitrary code via a crafted command/script
Dolibarr allows a remote privileged attacker to execute arbitrary code via a crafted command/script
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
ghsaosv
CVE-2023-33568HIGHPoC≥ 16.0.0, < 16.0.52023-06-13
CVE-2023-33568 [HIGH] CWE-200 Dolibarr vulnerable to unauthenticated database access
Dolibarr vulnerable to unauthenticated database access
An issue in Dolibarr v16.0.0 to v16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee information if a contact file exists.
ghsaosv
1 / 6Next →