VulnSea

dolibarr has 17 CVEs on record. Disclosure cadence is accelerating: 15 in the last 90 days against 1 in the 90 before. The busiest recent month was August 2026 with 13. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The dominant weakness classes are CWE-863 (5) and CWE-862 (3). Most affected products: Dolibarr (15), CRM (1), dolibarr_erp/crm (1).

CVEs per month

Last 12 months, by publish date

111201020304050607080910
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
—
Last 90 days
15 prev 1

Products

  • Dolibarr 15
  • CRM 1
  • dolibarr_erp/crm 1
17
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

dolibarr vulnerabilities

CVEs affecting dolibarr, newest first. Open any entry for full detail, references, and exploit status.

17 CVEsRSS

CVE-2026-89013High· 7.5PoC
3w ago

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value

Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files through the document storage endpoints by supplying a crafted hashp parameter value. Attackers can…

▾ MidnightDolibarr · DolibarrEPSS 1.6%via NVD
CVE-2026-89012Medium· 6.5PoC
3w ago

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows authenticated attackers to recover protected database fields by supplying uppercase variants of denyl…

▾ TwilightDolibarr · DolibarrEPSS 0.46%via NVD
CVE-2026-81729Medium· 6.5
1mo ago

Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion

Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs/api/class/api_documents.class.php calls dol_check_secure_access_document() with the mode argument 'read' when handli…

▾ SunlitDolibarr · dolibarrEPSS 0.39%via CVEORG
CVE-2026-81730High· 8.2
1mo ago

Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename

Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to a safe basename. The global saveAttachment() in htdocs/emailcollector/lib/emailcollector.lib.php b…

▾ TwilightDolibarr · dolibarrEPSS 0.56%via CVEORG
CVE-2026-81728High· 8.1
1mo ago

Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys

Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with GETPOST('updatekeys', 'array') in htdocs/imports/import.php, which applies only the generic alphanohtml filter: that…

▾ TwilightDolibarr · dolibarrEPSS 0.44%via CVEORG
CVE-2026-77923Medium· 4.3
1mo ago

Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action

Dolibarr 21.0.0 before 24.0.0 contains an authorization bypass vulnerability caused by an inverted boolean condition in the private-project membership check within the clonetasks mass action handler in htdocs/core/actions_massactions.inc…

▾ SunlitDolibarr · dolibarrEPSS 0.36%via CVEORG
CVE-2026-71511Medium· 6.5PoC
1mo ago

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticated attackers with member-read rights to retrieve bcrypt password verifiers by querying member endpoints. Attackers can…

▾ TwilightDolibarr · dolibarrEPSS 0.41%via NVD
CVE-2026-71510Medium· 6.5PoC
1mo ago

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses with…

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses with…

▾ TwilightDolibarr · dolibarrEPSS 0.38%via NVD
CVE-2026-71509Medium· 6.5PoC
1mo ago

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting a…

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint that allows authenticated attackers with expense-creation rights to bypass the approval workflow by directly setting a…

▾ TwilightDolibarr · dolibarrEPSS 0.42%via NVD
CVE-2026-71508Medium· 6.5PoC
1mo ago

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits…

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist that omits…

▾ TwilightDolibarr · dolibarrEPSS 0.39%via NVD
CVE-2026-71507Medium· 6.5PoC
1mo ago

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank a…

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account write routes that allows authenticated attackers with third-party creation rights to create, replace, or delete bank a…

▾ TwilightDolibarr · dolibarrEPSS 0.39%via NVD
CVE-2026-71506High· 8.1PoC
1mo ago

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the i…

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the payments REST API delete endpoint that allows authenticated attackers with invoice-deletion rights to permanently delete any payment record by bypassing the i…

▾ MidnightDolibarr · dolibarrEPSS 0.54%via NVD
CVE-2026-71505High· 7.1PoC
1mo ago

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal passw…

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API third-party site account write routes that allows authenticated attackers with third-party creation rights to overwrite the WebPortal passw…

▾ MidnightDolibarr · dolibarrEPSS 0.41%via NVD
CVE-2026-71504High· 8.1PoC
1mo ago

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without…

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without…

▾ MidnightDolibarr · dolibarrEPSS 0.46%via NVD
CVE-2026-71503Medium· 6.1PoC
1mo ago

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no …

Dolibarr before 24.0.0 contains a reflected cross-site scripting vulnerability in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block and no …

▾ TwilightDolibarr · dolibarrEPSS 0.37%via NVD
CVE-2025-67486High· 7.2
5mo ago

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionalit…

▾ Twilightdolibarr · dolibarr_erp/crmEPSS 0.88%via NVD
CVE-2021-47779Medium· 5.4PoC
8mo ago

Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation

Dolibarr ERP-CRM 14.0.2 contains a stored cross-site scripting vulnerability in the ticket creation module that allows low-privilege users to inject malicious scripts. Attackers can craft a specially designed ticket message with embedded…

▾ TwilightDolibarr · CRMEPSS 0.36%via CVEORG
dolibarr vulnerabilities (CVEs) · VulnSea