CVE-2012-10059
- EPSS 60.43%
- Published 13.08.2025 20:33:50
- Last modified 14.08.2025 15:15:31
Dolibarr ERP/CRM versions <= 3.1.1 and <= 3.2.0 contain a post-authenticated OS command injection vulnerability in its database backup feature. The export.php script fails to sanitize the sql_compat parameter, allowing authenticated users to inject a...
- EPSS 0.14%
- Published 27.01.2025 17:15:16
- Last modified 19.02.2025 20:15:35
A cross-site scripting (XSS) vulnerability in the Product module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
- EPSS 0.14%
- Published 27.01.2025 17:15:16
- Last modified 19.02.2025 20:15:35
A cross-site scripting (XSS) vulnerability in the Events/Agenda module of Dolibarr v21.0.0-beta allows attackers to execute arbitrary web scripts or HTMl via a crafted payload injected into the Title parameter.
CVE-2021-3991
- EPSS 0.1%
- Published 15.11.2024 11:15:07
- Last modified 19.11.2024 15:31:47
An Improper Authorization vulnerability exists in Dolibarr versions prior to the 'develop' branch. A user with restricted permissions in the 'Reception' section is able to access specific reception details via direct URL access, bypassing the intende...
CVE-2024-23817
- EPSS 0.61%
- Published 25.01.2024 20:15:41
- Last modified 21.11.2024 08:58:28
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Version 18.0.4 has a HTML Injection vulnerability in the Home page of the Dolibarr Application. This vulnerability allows an attacker to in...
CVE-2023-4198
- EPSS 0.08%
- Published 01.11.2023 09:15:09
- Last modified 21.11.2024 08:34:36
Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data
CVE-2023-4197
- EPSS 36.41%
- Published 01.11.2023 08:15:07
- Last modified 21.11.2024 08:34:36
Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.
CVE-2023-5842
- EPSS 0.11%
- Published 30.10.2023 01:15:22
- Last modified 21.11.2024 08:42:36
Cross-site Scripting (XSS) - Stored in GitHub repository dolibarr/dolibarr prior to 16.0.5.
CVE-2023-5323
- EPSS 0.21%
- Published 01.10.2023 01:15:24
- Last modified 21.11.2024 08:41:31
Cross-site Scripting (XSS) - Generic in GitHub repository dolibarr/dolibarr prior to 18.0.
CVE-2023-38888
- EPSS 3.04%
- Published 20.09.2023 01:15:56
- Last modified 21.11.2024 08:14:23
Cross Site Scripting vulnerability in Dolibarr ERP CRM v.17.0.1 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the REST API module, related to analyseVarsForSqlAndScriptsInjection and testSqlAndScri...