PatchSiren

Dolibarr CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Dolibarr CVE published 2026-09-11

CVE-2026-89012

CVE-2026-89012 is a case-sensitive denylist bypass vulnerability in Dolibarr's sqlfilters API query parameter. Authenticated attackers can recover protected database fields by supplying uppercase variants of denylist-protected field names, exploiting case-insensitive database column resolution against the case-sensitive denylist check. This allows attackers to extract full password hashes for any user acc [truncated]

MEDIUM Dolibarr CVE published 2026-08-30

CVE-2026-82633

Dolibarr versions 10.0.0 before 24.0.0 have a vulnerability in the Users::getGroups REST API endpoint. The vulnerability allows authenticated users to retrieve group memberships of other users by calling GET /users/{id}/groups with arbitrary user identifiers. This access can reveal group names, entity associations, and private notes across tenant boundaries.

HIGH Dolibarr CVE published 2026-08-27

CVE-2026-81730

The CVE-2026-81730 vulnerability affects Dolibarr ERP/CRM versions 9.0.0 through 23.0.4, allowing for path traversal attacks via email collector attachment filenames. This vulnerability has a high CVSS score of 8.8 and is classified as HIGH severity. The vulnerability is addressed in version 24.0.0, which applies dol_sanitizePathName() and dol_sanitizeFileName() before writing. Administrators and users of [truncated]

HIGH Dolibarr CVE published 2026-08-27

CVE-2026-81728

Dolibarr Erp/crm contains a SQL injection vulnerability in its CSV and XLSX import wizard prior to version 24.0.0. The vulnerability arises from the lack of proper sanitization of user-input data in the import.php and import_csv.modules.php files. An attacker with import permissions can exploit this vulnerability to exfiltrate arbitrary table content and potentially overwrite rows in certain tables.

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71511

CVE-2026-71511 is a sensitive data exposure vulnerability in Dolibarr's Members REST API. Authenticated attackers with member-read rights can retrieve bcrypt password verifiers by querying member endpoints, potentially enabling offline password cracking attacks. The vulnerability was published on 2026-08-24T20:17:13.420Z and last modified on 2026-09-08T20:23:49.880Z.

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71510

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers with user-read rights to extract sensitive data by splicing unsanitized filter parameters into SQL WHERE clauses without column restrictions. The vulnerability enables attackers to perform binary search on numeric fields and LIKE prefix iteration on string fields to recover sensitive inf [truncated]

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71509

CVE-2026-71509 is an improper authorization vulnerability in Dolibarr's expense report REST API update endpoint. Authenticated attackers with expense-creation rights can bypass approval workflows by directly setting approval status and approver identity fields, potentially advancing expense reports to approved or closed status. This vulnerability affects Dolibarr versions prior to 24.0.0 and requires veri [truncated]

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71508

CVE-2026-71508: Dolibarr Improper Authorization Vulnerability. The vulnerability exists in Dolibarr's user REST API update endpoint, allowing attackers with user-write rights to modify payroll fields by exploiting an incomplete credential denylist. This could lead to unauthorized changes in salary, bonus, hourly rate, daily rate, and weekly hours for any user. System administrators and security teams shou [truncated]

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71507

CVE-2026-71507 is a high-severity vulnerability in Dolibarr's REST API that allows authenticated attackers with third-party creation rights to create, replace, or delete bank account details of any company without requiring read access to that company. This could lead to unauthorized control of payment redirection. The vulnerability exists due to a broken object-level authorization mechanism in the REST A [truncated]

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71506

CVE-2026-71506 is an improper authorization vulnerability in Dolibarr's payments REST API delete endpoint. Authenticated attackers with invoice-deletion rights can bypass intended payment-issuance rights checks to permanently delete any payment record. This can lead to financial data integrity loss by zeroing paid amounts on invoices and removing entries from accounting exports.

HIGH Dolibarr CVE published 2026-08-24

CVE-2026-71504

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the Members REST API that allows attackers with only member-creation rights to reset the password of any user account, including the system administrator, without verifying password-change permissions. This vulnerability can lead to unauthorized access and system compromise if not addressed promptly. Defenders should assess exposur [truncated]

MEDIUM Dolibarr CVE published 2026-08-24

CVE-2026-71503

CVE-2026-71503 is a reflected cross-site scripting vulnerability in Dolibarr before version 24.0.0. The vulnerability exists in the extra fields administration template where the type request parameter is echoed without JavaScript-context encoding into an inline script block. No Content-Security-Policy header is emitted, making it possible for an unauthenticated attacker to cause an authenticated administ [truncated]

LOW Dolibarr CVE published 2026-06-09

CVE-2026-11619

A vulnerability was identified in Dolibarr ERP CRM up to 23.0.2. The impacted element is an unknown function of the file htdocs/core/filemanagerdol/connectors/php/config.inc.php of the component Legacy Filemanager. The manipulation leads to improper authorization. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 23.0.3 is sufficient [truncated]

LOW Dolibarr CVE published 2026-06-01

CVE-2026-10215

CVE-2026-10215 is a LOW-severity improper authorization vulnerability in Dolibarr ERP CRM versions up to 23.0.1, affecting the Leave Request REST API. The flaw resides in the `checkUserAccessToObject` function within `htdocs/holiday/class/api_holidays.class.php`, where insufficient access controls allow an authenticated, remote attacker to perform unauthorized operations on leave request records. The CVSS [truncated]

MEDIUM Dolibarr CVE published 2026-05-31

CVE-2026-10154

A medium-severity authorization bypass vulnerability exists in Dolibarr ERP CRM versions 23.0.0 through 23.0.2. The vulnerability is located in an unspecified function within htdocs/user/messaging.php, where manipulation of the ID parameter allows an attacker to bypass authorization controls. The attack vector is network-based and can be executed remotely. The vulnerability was published on 2026-05-31. Th [truncated]

HIGH Dolibarr CVE published 2026-05-27

CVE-2026-37713

A remote code execution vulnerability exists in Dolibarr ERP/CRM versions 22.0.0 through 22.0.4 and version 24.0.0-alpha. The vulnerability is located in htdocs/core/class/commonobject.class.php and allows a remote attacker to execute arbitrary code. The CVE was published on 2026-05-27 and subsequently modified the same day. The vulnerability status is currently marked as Deferred in the NVD. Two source r [truncated]

HIGH Dolibarr CVE published 2026-05-27

CVE-2026-37712

CVE-2026-37712 describes a remote code execution vulnerability in Dolibarr ERP/CRM affecting versions 22.0.0 through 22.0.4 and version 24.0.0-alpha. The issue resides in htdocs/cron/class/cronjob.class.php where unsafe use of call_user_func_array() in job type processing allows attackers to execute arbitrary code. The vulnerability was published to NVD on 2026-05-27 and modified later the same day. The C [truncated]

HIGH Dolibarr CVE published 2026-05-27

CVE-2026-37711

A remote code execution vulnerability exists in Dolibarr ERP/CRM versions 22.0.0 through 22.0.4 and version 24.0.0-alpha. The vulnerability is located in htdocs/core/actions_addupdatedelete.inc.php and allows unauthenticated remote attackers to execute arbitrary code on affected systems. The CVSS 3.1 score of 7.3 (HIGH) reflects network attack vector with low attack complexity, no required privileges, and [truncated]

CRITICAL Dolibarr CVE published 2026-05-23

CVE-2018-25357

A critical remote code execution vulnerability exists in Dolibarr ERP CRM 7.0.3. The vulnerability allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious payloads through the db_name parameter during the installation process. The attack vector involves sending a POST request to install/step1.php with crafted PHP code in the db_name parameter, followed by command execution vi [truncated]

HIGH Dolibarr CVE published 2026-05-08

CVE-2025-67486

CVE-2025-67486 is an authenticated remote code execution vulnerability in Dolibarr ERP/CRM software versions 22.0.2 and earlier. The vulnerability exists in the user extrafields functionality where user-controlled input is passed to PHP's `eval()` function without adequate sanitization. This allows authenticated administrators to execute arbitrary PHP code on the server. As of the time of publication, no [truncated]

HIGH Dolibarr CVE published 2026-04-21

CVE-2026-31018

CVE-2026-31018 is a high-severity vulnerability in Dolibarr ERP & CRM 22.0.4 and earlier. The vulnerability allows an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation. This issue arises from inconsistent application of PHP code detection and editing permission enforcement in the Website module.

HIGH Dolibarr CVE published 2026-04-12

CVE-2019-25710

Dolibarr ERP-CRM 8.0.4 contains an SQL injection vulnerability in the rowid parameter of the admin dict.php endpoint. This allows attackers to execute arbitrary SQL queries, potentially leading to sensitive database information extraction via error-based SQL injection techniques. The vulnerability requires immediate attention from administrators and security teams to prevent potential exploitation and dat [truncated]

HIGH Dolibarr CVE published 2026-04-07

CVE-2026-22666

CVE-2026-22666 is an authenticated remote code execution vulnerability in Dolibarr ERP/CRM versions prior to 23.0.2. The vulnerability exists in the dol_eval_standard() function, which fails to apply forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax. Attackers with administrator privileges can inject malicious payloads through computed extrafields or other evaluatio [truncated]