Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
dolibarr erp crm vulnerabilities and exploits
(subscribe to this query)
3.5
CVSSv2
CVE-2020-13828
Dolibarr 11.0.4 is affected by multiple stored Cross-Site Scripting (XSS) vulnerabilities that could allow remote authenticated malicious users to inject arbitrary web script or HTML via ticket/card.php?action=create with the subject, message, or address parameter; adherents/card...
Dolibarr Dolibarr Erp\\/crm 11.0.4
4.3
CVSSv2
CVE-2022-30875
Dolibarr 12.0.5 is vulnerable to Cross Site Scripting (XSS) via Sql Error Page.
Dolibarr Dolibarr Erp\\/crm 12.0.5
3.5
CVSSv2
CVE-2020-13239
The DMS/ECM module in Dolibarr 11.0.4 renders user-uploaded .html files in the browser when the attachment parameter is removed from the direct download link. This causes XSS.
Dolibarr Dolibarr Erp\\/crm 11.0.4
5.5
CVSSv2
CVE-2020-13240
The DMS/ECM module in Dolibarr 11.0.4 allows users with the 'Setup documents directories' permission to rename uploaded files to have insecure file extensions. This bypasses the .noexe protection mechanism against XSS.
Dolibarr Dolibarr Erp\\/crm 11.0.4
4.3
CVSSv2
CVE-2020-7994
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 10.0.6 allow remote malicious users to inject arbitrary web script or HTML via the (1) label[libelle] parameter to the /htdocs/admin/dict.php?id=3 page; the (2) name[constname] parameter to the /htdocs/admin/const.ph...
Dolibarr Dolibarr Erp\\/crm 10.0.6
7.5
CVSSv2
CVE-2013-2091
SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote malicious users to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.
Dolibarr Dolibarr Erp\\/crm 3.3.1
10
CVSSv2
CVE-2013-2093
Dolibarr ERP/CRM 3.3.1 does not properly validate user input in viewimage.php and barcode.lib.php which allows remote malicious users to execute arbitrary commands.
Dolibarr Dolibarr Erp\\/crm 3.3.1
6.5
CVSSv2
CVE-2014-7137
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM prior to 3.6.1 allow remote authenticated users to execute arbitrary SQL commands via the (1) contactid parameter in an addcontact action, (2) ligne parameter in a swapstatut action, or (3) project_ref parameter to projet...
Dolibarr Dolibarr
4.3
CVSSv2
CVE-2018-19799
Dolibarr ERP/CRM up to and including 8.0.3 has /exports/export.php?datatoexport= XSS.
Dolibarr Dolibarr
7.5
CVSSv2
CVE-2018-10094
SQL injection vulnerability in Dolibarr prior to 7.0.2 allows remote malicious users to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
Dolibarr Dolibarr
1 EDB exploit
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
inject
CVE-2024-34001
CVE-2024-37018
LFI
CVE-2024-1275
CVE-2024-1086
CSRF
CVE-2024-31030
CVE-2024-24919
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
4
5
6
7
8
9
10
NEXT »