Known Vulnerabilities for products from Dolibarr
Listed below are 20 of the newest known vulnerabilities associated with the vendor "Dolibarr".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-89013 json | Not Provided | 2026-09-11 | 2026-09-11 | |
| CVE-2026-89012 json | Not Provided | 2026-09-11 | 2026-09-11 | |
| CVE-2026-85401 json | Not Provided | 2026-09-04 | 2026-09-04 | |
| CVE-2026-82633 json | Not Provided | 2026-08-30 | 2026-08-31 | |
| CVE-2026-81730 json | Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without r... | Not Provided | 2026-08-27 | 2026-08-31 |
| CVE-2026-81729 json | Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/... | Not Provided | 2026-08-27 | 2026-08-31 |
| CVE-2026-81728 json | Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETP... | Not Provided | 2026-08-27 | 2026-08-31 |
| CVE-2026-78160 json | Not Provided | 2026-08-24 | 2026-08-24 | |
| CVE-2026-77923 json | Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the p... | Not Provided | 2026-08-24 | 2026-08-31 |
| CVE-2026-77686 json | Not Provided | 2026-08-21 | 2026-08-21 | |
| CVE-2026-34036 json | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions 22... | Not Provided | 2026-03-31 | 2026-04-03 |
| CVE-2026-31019 json | In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dang... | Not Provided | 2026-04-21 | 2026-07-05 |
| CVE-2026-31018 json | In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied c... | Not Provided | 2026-04-21 | 2026-07-05 |
| CVE-2026-23500 json | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions pr... | Not Provided | 2026-04-17 | 2026-05-01 |
| CVE-2026-22666 json | Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticated remote code execution vulnerability in the dol_eval_standa... | Not Provided | 2026-04-07 | 2026-07-14 |
| CVE-2025-67486 json | Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.... | Not Provided | 2026-05-08 | 2026-05-12 |
| CVE-2025-56588 json | Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configur... | Not Provided | 2025-10-01 | 2026-07-05 |
| CVE-2024-37821 json | An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to ... | Not Provided | 2024-06-18 | 2026-07-09 |
| CVE-2024-29477 json | Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent ac... | Not Provided | 2024-04-03 | 2026-07-09 |
| CVE-2024-23817 json | 6.1 - MEDIUM | 2024-01-25 | 2024-01-31 |
Known software with vulnerabilities from Dolibarr
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Dolibarr | Dolibarr | 10.0.1 |
| Application | Dolibarr | Dolibarr Erp/crm | 2.8.1 |