CVE-2026-89013
- EPSS 0.37%
- Veröffentlicht 11.09.2026 15:54:59
- Zuletzt bearbeitet 23.09.2026 17:17:46
Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can send a reque...
CVE-2026-89012
- EPSS 0.34%
- Veröffentlicht 11.09.2026 15:49:17
- Zuletzt bearbeitet 23.09.2026 17:17:46
Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denylist-protected...
CVE-2026-85401
- EPSS 0.25%
- Veröffentlicht 04.09.2026 02:45:11
- Zuletzt bearbeitet 04.09.2026 19:17:31
A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy File Manager. Executing a manipul...
CVE-2026-82633
- EPSS 0.21%
- Veröffentlicht 30.08.2026 12:34:51
- Zuletzt bearbeitet 10.09.2026 15:53:23
Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups wit...
CVE-2026-81730
- EPSS 0.38%
- Veröffentlicht 27.08.2026 20:07:34
- Zuletzt bearbeitet 31.08.2026 18:08:50
Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php builds $filepa...
CVE-2026-81729
- EPSS 0.22%
- Veröffentlicht 27.08.2026 20:07:34
- Zuletzt bearbeitet 31.08.2026 19:17:14
Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handling DELETE /ap...
CVE-2026-81728
- EPSS 0.26%
- Veröffentlicht 27.08.2026 20:07:33
- Zuletzt bearbeitet 31.08.2026 18:05:29
Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that strips HTML ...
CVE-2026-77923
- EPSS 0.21%
- Veröffentlicht 24.08.2026 19:23:28
- Zuletzt bearbeitet 31.08.2026 18:45:46
Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc.php. Authent...
CVE-2026-71511
- EPSS 0.24%
- Veröffentlicht 24.08.2026 19:06:35
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can call the ind...
CVE-2026-71510
- EPSS 0.23%
- Veröffentlicht 24.08.2026 19:05:39
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column re...