pkg:Packagist/dolibarr/dolibarr

123 total CVEsCRITICAL27HIGH36MEDIUM57LOW1

✅ Check your installed version

All known vulnerabilities

  • CRITICAL9.8CVE-2022-4093SQL Injection in dolibarr/dolibarr
    >= 16.0.1, < 16.0.3
  • CRITICAL9.8CVE-2022-43138Dolibarr vulnerable to privilege escalation
    from 0, < 14.0.1
  • CRITICAL9.8CVE-2022-40871Dolibarr vulnerable to Eval Injection
    from 0, <= 15.0.3
  • CRITICAL9.8CVE-2021-33816Dolibarr remote PHP code execution
    >= 13.0.2, < 14.0.0
  • CRITICAL9.8CVE-2019-19212Dolibarr Cross-site Scripting via the qty parameter in product/fournisseurs.php
    >= 3.0, <= 10.0.3
  • CRITICAL9.8CVE-2020-7995Dolibarr Improper Restriction of Excessive Authentication Attempts
  • CRITICAL9.8CVE-2017-7888Dolibarr ERP and CRM Insecure Encryption
    from 0, <= 4.0.4
  • CRITICAL9.8CVE-2017-7886Dolibarr SQL Injection in doli/theme/eldy/style.css.php via the lang parameter
  • CRITICAL9.8CVE-2017-9435Dolibarr ERP and CRM SQLi
    from 0, < 5.0.3
  • CRITICAL9.8CVE-2017-14238Dolibarr SQL injection vulnerability in admin/menus/edit.php
    from 0, < 6.0.1
  • CRITICAL9.8CVE-2017-14242Dolibarr SQL injection vulnerability in don/list.php
    from 0, < 6.0.1
  • CRITICAL9.8CVE-2017-17897Dolibarr SQL injection vulnerability in comm/multiprix.php
    from 0, < 6.0.5
  • CRITICAL9.8CVE-2017-17899Dolibarr SQL injection vulnerability in adherents/subscription/info.php
    from 0, < 6.0.5
  • CRITICAL9.8CVE-2017-17900Dolibarr SQL injection vulnerability in fourn/index.php
    from 0, < 6.0.5
  • CRITICAL9.8CVE-2018-10094Dolibarr SQL injection vulnerability
    from 0, < 7.0.2
  • CRITICAL9.8CVE-2018-13448Dolibarr SQL injection vulnerability in product/card.php
    >= 7.0.3, < 7.0.4
  • CRITICAL9.8CVE-2018-13447Dolibarr SQL injection vulnerability in product/card.php
    >= 7.0.3, < 7.0.4
  • CRITICAL9.8CVE-2018-13449Dolibarr SQL injection vulnerability in product/card.php
    >= 7.0.3, < 7.0.4
  • CRITICAL9.8CVE-2018-13450Dolibarr SQL injection vulnerability in product/card.php
    >= 7.0.3, < 7.0.4
  • CRITICAL9.8CVE-2018-16809Dolibarr SQL injection via the integer parameters qty and value_unit
    >= 3.8, <= 7.0.0
  • CRITICAL9.8CVE-2018-9019Dolibarr SQL Injection vulnerability
    from 0, < 7.0.2
  • CRITICAL9.6CVE-2023-38888Cross Site Scripting vulnerability in Dolibarr ERP CRM
    from 0, < 17.0.1
  • CRITICAL9.1CVE-2026-23500Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration
    from 0, <= 22.0.4
  • CRITICAL9.1CVE-2024-5315Multiple vulnerabilities in DOLIBARR's ERP CMS
    from 0, <= 9.0.1
  • CRITICAL9.1CVE-2024-5314Multiple vulnerabilities in DOLIBARR's ERP CMS
    from 0, <= 9.0.1
  • CRITICAL9.0CVE-2024-55227Dolibarr Cross-site Scripting vulnerability
  • CRITICAL9.0CVE-2021-25955Dolibarr Cross-site Scripting vulnerability
    >= 2.8.1, < 14.0.0
  • HIGH8.8CVE-2026-31019Dolibarr user with permission to edit PHP content can bypass filtering to restrict dangerous PHP functions
    from 0, <= 22.0.4
  • HIGH8.8CVE-2026-31018Dolibarr Allows Code Injection through its Website Module
    from 0, <= 15.0.3
  • HIGH8.8CVE-2025-56588Dolibarr vulnerable to RCE via the computed field parameter
    from 0, < 21.0.3
  • HIGH8.8CVE-2024-37821Dolibarr arbitrary file upload vulnerability
    from 0, < 19.0.2
  • HIGH8.8CVE-2023-38887File Upload vulnerability in Dolibarr ERP CRM
    from 0, < 17.0.1
  • HIGH8.8CVE-2023-30253Dolibarr vulnerable to remote code execution via uppercase manipulation
    from 0, < 17.0.1
  • HIGH8.8CVE-2020-14209Dolibarr Unrestricted Upload of File with Dangerous Type
    from 0, < 11.0.5
  • HIGH8.8CVE-2020-14443Dolibarr SQL injection vulnerability in accountancy/customer/card.php
    from 0, < 11.0.5
  • HIGH8.8CVE-2020-12669Incorrect Authorization in Dolibarr
    from 0, < 12.0.0
  • HIGH8.8CVE-2020-11825Dolibarr Cross-Site Request Forgery Vulnerability
    from 0, <= 10.0.6
  • HIGH8.8CVE-2019-11200Dolibarr ERP and CRM malicious executable loading
    from 0, < 9.0.3
  • HIGH8.8CVE-2019-1010054Dolibarr Cross Site Request Forgery (CSRF)
  • HIGH8.8CVE-2017-9840Dolibarr ERP and CRM Unsafe File Upload Vulnerability
    from 0, <= 5.0.3
  • HIGH8.8CVE-2017-9839Dolibarr SQL injection via type parameter in product/stats/card.php
    from 0, < 5.0.4
  • HIGH8.8CVE-2017-18260Dolibarr SQL injection vulnerability
    from 0, <= 7.0.0
  • HIGH8.8CVE-2018-19994Dolibarr error-based SQL injection vulnerability in product/card.php
    from 0, < 8.0.4
  • HIGH8.8CVE-2018-19998Dolibarr SQL injection vulnerability in user/card.php
    from 0, < 8.0.4
  • HIGH8.8CVE-2021-36625SQL Injection in Dolibarr
    from 0, < 14.0.0
  • HIGH8.8CVE-2022-0819Code Injection in dolibarr/dolibarr
    from 0, < 15.0.1
  • HIGH8.8CVE-2021-25957Weak Password Recovery Mechanism for Forgotten Password
    from 0, < 14.0.0
  • HIGH8.3CVE-2022-0224SQL Injection in dolibarr/dolibarr
    from 0, <= 14.0.5
  • HIGH8.2CVE-2019-25710Dolibarr has SQL injection vulnerability in the rowid parameter of the admin dict.php
    from 0, <= 8.0.4
  • HIGH8.0CVE-2019-15062Dolibarr Cross-Site Request Forgery (CSRF)
    >= 10.0, < 10.0.2
  • HIGH8.0CVE-2019-11201Dolibarr ERP and CRM Code Injection
    from 0, < 9.0.3
  • HIGH8.0CVE-2018-10092Dolibarr arbitrary commands execution
    from 0, < 7.0.2
  • HIGH7.5CVE-2024-31503Dolibarr vulnerable to Cross-Site Request Forgery
    from 0, <= 19.0.0
  • HIGH7.5CVE-2023-4197Dolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCE
    from 0, < 18.0.2
  • HIGH7.5CVE-2023-33568Dolibarr vulnerable to unauthenticated database access
    >= 16.0.0, < 16.0.5
  • HIGH7.5CVE-2019-19209Dolibarr ERP and CRM SQLi
    from 0, < 10.0.3
  • HIGH7.5CVE-2017-14240Dolibarr ERP and CRM Sensitive Data Disclosure
    from 0, < 6.0.1
  • HIGH7.5CVE-2017-17898Dolibarr sensitive information disclosure
    from 0, < 6.0.5
  • HIGH7.5CVE-2021-37517Access Control vulnerability in Dolibarr
    from 0, < 14.0.1
  • HIGH7.2CVE-2023-38886Dolibarr allows a remote privileged attacker to execute arbitrary code via a crafted command/script
    from 0, < 17.0.1
  • HIGH7.2CVE-2020-35136Dolibarr authenticated Remote Code Execution
    from 0, < 12.0.4
  • HIGH7.2CVE-2021-25956Improper User Access Control in "Dolibarr" Leads to Account Takeover
    >= 3.3.beta1, < 14.0.0
  • HIGH7.1CVE-2024-23817Dolibarr Application Home Page HTML injection vulnerability
    >= 18.0.4, < 18.0.7
  • MEDIUM6.8CVE-2024-29477Dolibarr ERP CRM Code Injection vulnerability during installation
    from 0, <= 19.0.0
  • MEDIUM6.8CVE-2017-8879Dolibarr allows password changes without supplying the current password
  • MEDIUM6.5CVE-2026-34036Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.php
    from 0, <= 22.0.4
  • MEDIUM6.5CVE-2023-4198Dolibarr ERP CRM (<= 17.0.3) Improper Access Control
    from 0, < 18.0.0
  • MEDIUM6.5CVE-2020-14201Dolibarr CRM allows Privilege Escalation
    from 0, < 11.0.5
  • MEDIUM6.5CVE-2022-0731Improper Access Control (IDOR) in dolibarr/dolibarr
    from 0, < 16.0
  • MEDIUM6.1CVE-2022-30875Cross-site Scripting in Dolibarr
  • MEDIUM6.1CVE-2021-33618Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, <= 13.0.2
  • MEDIUM6.1CVE-2020-14475Dolibarr reflected cross-site scripting (XSS) vulnerability
    from 0, < 11.0.5
  • MEDIUM6.1CVE-2019-19211Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, < 10.0.3
  • MEDIUM6.1CVE-2020-7994Dolibarr cross-site scripting (XSS) vulnerability
  • MEDIUM6.1CVE-2019-17223Dolibarr ERP and CRM HTML Injection
    from 0, < 11.0.1
  • MEDIUM6.1CVE-2019-1010016Dolibarr Cross Site Scripting (XSS)
  • MEDIUM6.1CVE-2017-7887Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, <= 4.0.4
  • MEDIUM6.1CVE-2017-17971Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, < 6.0.5
  • MEDIUM6.1CVE-2018-10095Dolibarr Cross-site scripting (XSS) vulnerability
    from 0, < 7.0.2
  • MEDIUM6.1CVE-2018-19993Dolibarr reflected cross-site scripting (XSS) vulnerability
    from 0, < 8.0.4
  • MEDIUM6.1CVE-2018-19799Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, <= 8.0.3
  • MEDIUM6.1CVE-2018-16808Dolibarr Stored Cross-site Scripting in expensereport/card.php
    from 0, < 7.0.1
  • MEDIUM6.1CVE-2020-7996XSS in Dolibarr ERP & CRM
    from 0, <= 10.0.6
  • MEDIUM6.1CVE-2019-16197Cross-site scripting in Dolibarr
    from 0, < 10.0.2
  • MEDIUM5.5CVE-2024-40137Dolibarr ERP CRM vulnerable to remote code execution (RCE)
    from 0, < 19.0.2
  • MEDIUM5.4CVE-2024-55228Dolibarr Cross-site Scripting vulnerability
  • MEDIUM5.4CVE-2023-5323Cross-site Scripting (XSS) - Generic in dolibarr/dolibarr
    from 0, < 18.0.0
  • MEDIUM5.4CVE-2022-2060Cross-site Scripting (XSS) - Stored in dolibarr/dolibarr
    from 0, < 16.0
  • MEDIUM5.4CVE-2020-13828Dolibarr stored Cross-Site Scripting (XSS) vulnerability
    from 0, <= 11.0.4
  • MEDIUM5.4CVE-2020-13239Dolibarr Stored Cross-site Scripting via file upload
  • MEDIUM5.4CVE-2020-13240Dolibarr Stored Cross-site Scripting
  • MEDIUM5.4CVE-2020-11823Dolibarr stored Cross-site Scripting vulnerability
  • MEDIUM5.4CVE-2019-19210Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, < 10.0.3
  • MEDIUM5.4CVE-2020-9016Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, <= 11.0.0
  • MEDIUM5.4CVE-2019-19206Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, <= 10.0.3
  • MEDIUM5.4CVE-2019-17576Dolibarr Cross-site Scripting via outgoing email setup feature
  • MEDIUM5.4CVE-2019-17578Dolibarr Cross-site Scripting vulnerability
  • MEDIUM5.4CVE-2019-17577Dolibarr Cross-site Scripting via outgoing email setup feature
  • MEDIUM5.4CVE-2019-16687Dolibarr Cross-site Scripting in a User Profile in a Signature section
  • MEDIUM5.4CVE-2019-16688Dolibarr stored Cross-site Scripting in an Email Template section
  • MEDIUM5.4CVE-2019-16686Dolibarr Cross-site Scripting in a User Note section
  • MEDIUM5.4CVE-2019-16685Dolibarr stored Cross-site Scripting vulnerability
  • MEDIUM5.4CVE-2016-1912Dolibarr ERP and CRM contain XSS Vulnerabilities
    from 0, <= 3.8.3
  • MEDIUM5.4CVE-2017-14241Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, < 6.0.1
  • MEDIUM5.4CVE-2017-14239Dolibarr cross-site scripting (XSS) vulnerability
    >= 6.0.0, < 6.0.1
  • MEDIUM5.4CVE-2017-1000509Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, < 7.0.0
  • MEDIUM5.4CVE-2017-18259Dolibarr ERP and CRM contain XSS Vulnerability
    from 0, <= 7.0.0
  • MEDIUM5.4CVE-2017-9838Dolibarr Cross-Site Scripting (XSS) vulnerability
    from 0, < 5.0.4
  • MEDIUM5.4CVE-2018-19995Dolibarr stored cross-site scripting (XSS) vulnerability
    from 0, < 8.0.4
  • MEDIUM5.4CVE-2018-19992Dolibarr stored cross-site scripting (XSS) vulnerability
    from 0, < 8.0.4
  • MEDIUM5.4CVE-2022-22293Cross site scripting in dolibarr
    from 0, < 13.0.0
  • MEDIUM5.4CVE-2021-42220Dolibarr Cross Site Scripting (XSS) vulnerability
    from 0, < 14.0.3
  • MEDIUM5.4CVE-2020-13094XSS in Dolibarr
    from 0, < 11.0.4
  • MEDIUM5.0CVE-2026-7688Dolibarr has an Injection issue
    from 0, <= 23.0.2
  • MEDIUM4.8CVE-2023-5842Cross-site Scripting (XSS) - Stored in dolibarr/dolibarr
    from 0, < 16.0.5
  • MEDIUM4.3CVE-2021-3991Improper Authorization in dolibarr/dolibarr
    from 0, < 15.0.0
  • MEDIUM4.3CVE-2022-0746Business Logic Errors in dolibarr/dolibarr
    from 0, < 16.0
  • MEDIUM4.3CVE-2022-0414Improper Validation of Specified Quantity in Input in dolibarr/dolibarr
    from 0, < 15.0
  • MEDIUM4.3CVE-2022-0174Improper Validation of Specified Quantity in Input in dolibarr/dolibarr
    from 0, < 15.0.0
  • MEDIUM4.3CVE-2021-25954Improper Access Control in Dolibarr
    >= 2.8.1, < 14.0.0
  • LOW3.7CVE-2026-7689Dolibarr has Insufficient Verification of Data Authenticity
    from 0, <= 15.0.3
  • CVE-2024-34051Reflected Cross-Site Scripting (XSS) in Dolibarr
    from 0, < 19.0.2
  • CVE-2015-3935Dolibarr ERP and CRM contain Cross-site Scripting Vulnerability
    >= 3.5.0, < 3.5.8