CVE-2026-71509
- EPSS 0.24%
- Veröffentlicht 24.08.2026 19:04:52
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting approval statu...
CVE-2026-71508
- EPSS 0.22%
- Veröffentlicht 24.08.2026 19:03:59
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits payroll colu...
CVE-2026-71507
- EPSS 0.22%
- Veröffentlicht 24.08.2026 19:03:01
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account detail...
CVE-2026-71506
- EPSS 0.3%
- Veröffentlicht 24.08.2026 19:01:47
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the intended payme...
CVE-2026-71505
- EPSS 0.23%
- Veröffentlicht 24.08.2026 19:00:47
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal password of any co...
CVE-2026-71504
- EPSS 0.26%
- Veröffentlicht 24.08.2026 18:57:47
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying pa...
CVE-2026-71503
- EPSS 0.21%
- Veröffentlicht 24.08.2026 18:57:05
- Zuletzt bearbeitet 08.09.2026 20:23:49
Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Secur...
CVE-2026-77686
- EPSS 0.27%
- Veröffentlicht 21.08.2026 11:00:13
- Zuletzt bearbeitet 24.08.2026 16:41:13
A weakness has been identified in Dolibarr up to 23.0.4. This affects an unknown part of the file htdocs/user/card.php of the component Account Handler. This manipulation of the argument ID causes improper authorization. The attack may be initiated r...
CVE-2026-19930
- EPSS 0.24%
- Veröffentlicht 16.08.2026 03:15:09
- Zuletzt bearbeitet 20.08.2026 12:48:10
A security flaw has been discovered in Dolibarr up to 23.0.3. Affected is an unknown function of the file htdocs/user/card.php of the component User Cloning. The manipulation of the argument ID results in ldap injection. It is possible to launch the ...
CVE-2026-58376
- EPSS 0.22%
- Veröffentlicht 30.06.2026 15:59:10
- Zuletzt bearbeitet 14.07.2026 22:17:29
Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API users to exfiltrate arbitrary database contents by supplying malicious values to the sqlfilters query parameter in the setup dictio...