---
id: CVE-2026-71503
title: >-
  Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability
  in the extra fields administration template where the type request parameter
  is echoed without JavaScript-context encoding into an inline script block and
  no …
summary: >-
  Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability
  in the extra fields administration template where the type request parameter
  is echoed without JavaScript-context encoding into an inline script block and
  no …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-08-24'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T20:23:49.880'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-71503'
references:
  - url: >-
      https://codeant.ai/security-research/cve-2026-71503-reflected-xss-via-the-type-parameter
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Dolibarr/dolibarr/commit/3094b0aa3b500ff51020b660a7e66ffcb9d1cd91
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Dolibarr/dolibarr/releases/tag/24.0.0'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/dolibarr-reflected-xss-via-extra-fields-administration-template
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00211
epssPercentile: 0.11637
ingestedAt: '2026-09-08T21:11:12.284Z'
---

## Overview

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no Content-Security-Policy header is emitted. An unauthenticated attacker can cause an authenticated administrator to open a crafted URL to execute arbitrary JavaScript in that session and create a persistent administrator account.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
