Dolibarr

Dolibarr Erp/crm

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.38%
  • Veröffentlicht 27.08.2026 20:07:34
  • Zuletzt bearbeitet 31.08.2026 18:08:50

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepa...

  • EPSS 0.26%
  • Veröffentlicht 27.08.2026 20:07:33
  • Zuletzt bearbeitet 31.08.2026 18:05:29

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML ...

  • EPSS 0.21%
  • Veröffentlicht 24.08.2026 19:23:28
  • Zuletzt bearbeitet 31.08.2026 18:45:46

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authent...

  • EPSS -
  • Veröffentlicht 18.08.2026 13:39:16
  • Zuletzt bearbeitet 18.08.2026 16:18:17

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Exploit
  • EPSS 0.92%
  • Veröffentlicht 17.04.2026 20:25:49
  • Zuletzt bearbeitet 01.05.2026 18:28:29

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates the MAIN_ODT_AS_PDF configuration constant directly...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 12.04.2026 12:28:54
  • Zuletzt bearbeitet 17.04.2026 14:25:58

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint that allows attackers to execute arbitrary SQL queries. Attackers can inject malicious SQL code through the rowid POST parameter to e...

Exploit
  • EPSS 15.53%
  • Veröffentlicht 07.04.2026 12:41:31
  • Zuletzt bearbeitet 14.07.2026 16:16:50

Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standard() function that fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. ...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 22.02.2026 13:18:25
  • Zuletzt bearbeitet 02.03.2026 15:16:24

Dolibarr ERP/CRM 10.0.1 contains an SQL injection vulnerability in the elemid POST parameter of the viewcat.php endpoint that allows unauthenticated attackers to execute arbitrary SQL queries. Attackers can submit crafted POST requests with malicious...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 22.02.2026 13:18:24
  • Zuletzt bearbeitet 02.03.2026 15:16:23

Dolibarr ERP/CRM 10.0.1 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries by injecting SQL code through POST parameters. Attackers can inject malicious SQL through parameters like action...

Exploit
  • EPSS 3.1%
  • Veröffentlicht 13.08.2025 20:33:50
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject a...