Vulnerabilities (CVE)

Filtered by vendor Dolibarr Subscribe
Total 142 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2011-4802 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-16 6.5 MEDIUM N/A
Multiple SQL injection vulnerabilities in Dolibarr 3.1.0 RC and probably earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) sortfield, (2) sortorder, and (3) sall parameters to user/index.php and (b) user/group/index.php; the id parameter to (4) info.php, (5) perms.php, (6) param_ihm.php, (7) note.php, and (8) fiche.php in user/; and (9) rowid parameter to admin/boxes.php.
CVE-2011-4329 1 Dolibarr 1 Dolibarr Erp\/crm 2026-06-16 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr 3.1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter in a setup action to admin/company.php, or the PATH_INFO to (2) admin/security_other.php, (3) admin/events.php, or (4) admin/user.php.