Vulnerabilities (CVE)

Vendor filter

Dolibarr Subscribe

Product filter

Dolibarr Subscribe

Filter

50 total CVE
CVE Vendors Products Updated CVSS
CVE-2017-7886 1 Dolibarr 1 Dolibarr 2017-05-15 7.5
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.
CVE-2017-7888 1 Dolibarr 1 Dolibarr 2017-05-15 5.0
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.
CVE-2017-7887 1 Dolibarr 1 Dolibarr 2017-05-15 4.3
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.
CVE-2015-8685 1 Dolibarr 1 Dolibarr 2016-12-07 4.3
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) external calendar url or (2) the bank name field in the "import external calendar" page.
CVE-2015-3935 1 Dolibarr 1 Dolibarr 2016-12-06 4.3
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (search_nom) field to (1) htdocs/societe/societe.php or (2)...
CVE-2016-1912 1 Dolibarr 1 Dolibarr 2016-01-22 3.5
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.8.3 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lastname, (2) firstname, (3) email, (4) job, or (5) signature parameter to...
CVE-2014-3992 1 Dolibarr 1 Dolibarr 2014-07-11 6.5
Multiple SQL injection vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote authenticated users to execute arbitrary SQL commands via the (1) entity parameter in an update action to user/fiche.php or (2) sortorder parameter to user/group/index.php.
CVE-2014-3991 1 Dolibarr 1 Dolibarr 2014-07-11 4.3
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) dol_use_jmobile, (2) dol_optimize_smallscreen, (3) dol_no_mouse_hover, (4) dol_hide_topmenu,...
CVE-2012-1225 1 Dolibarr 1 Dolibarr 2012-02-24 7.5
Multiple SQL injection vulnerabilities in Dolibarr CMS 3.2.0 Alpha and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) memberslist parameter (aka Member List) in list.php or (2) rowid parameter to...
CVE-2011-4329 1 Dolibarr 1 Dolibarr 2012-02-17 4.3
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2)...