Dolibarr is an open-source enterprise resource planning and customer relationship management platform widely deployed across small and medium-sized businesses and organizational backends, concentrating its vulnerability footprint in a single product line that punches above its typical adoption scale. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the web application's broad attack surface and appeal to both security researchers and threat actors. The exposure recurs persistently through application-layer weakness classes including cross-site scripting, SQL injection, code injection, improper access control, and cross-site request forgery—signature flaws in web-facing business software that can lead to data compromise, privilege escalation, and system takeover. Defenders deploying Dolibarr should treat updates as high-priority, restrict internet exposure where feasible, and implement compensating controls such as web application firewalls; current severity, exploitation, and public-exploit counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dolibarr over time
Signals from CVEs in this vendor scope (140 CVEs).
140 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-10094CRITICAL SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes. | May 22, 2018 | 9.8 | 85 | NO | YES |
CVE-2023-30253HIGH Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data. | May 29, 2023 | 8.8 | 80 | NO | YES |
CVE-2018-10095MEDIUM Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/ | May 22, 2018 | 6.1 | 76 | NO | YES |
CVE-2021-33618MEDIUM Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature. | Nov 10, 2021 | 6.1 | 64 | NO | NO |
CVE-2024-5315CRITICAL Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query t | May 24, 2024 | 9.1 | 56 | NO | YES |
CVE-2012-1226HIGH Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in th | Feb 21, 2012 | 7.5 | 54 | NO | YES |
CVE-2022-0819HIGH Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1. | Mar 2, 2022 | 8.8 | 52 | NO | NO |
CVE-2020-14209HIGH Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded. | Sep 2, 2020 | 8.8 | 52 | NO | YES |
CVE-2022-40871CRITICAL Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious c | Oct 12, 2022 | 9.8 | 49 | NO | NO |
CVE-2023-33568HIGH An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee in | Jun 13, 2023 | 7.5 | 48 | NO | YES |
Signals from CVEs in this vendor scope (140 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dolibarr.
Media articles that mention a CVE ID that affects a product developed by Dolibarr — matched by CVE ID, not by vendor name.