Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Dolibarr

First CVE: Nov 28, 2011Active for: 15 yearsTotal CVEs: 140
56.3
VTI Score
TOP TARGET

Dolibarr is an open-source enterprise resource planning and customer relationship management platform widely deployed across small and medium-sized businesses and organizational backends, concentrating its vulnerability footprint in a single product line that punches above its typical adoption scale. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a strong tendency to acquire public exploit code, reflecting the web application's broad attack surface and appeal to both security researchers and threat actors. The exposure recurs persistently through application-layer weakness classes including cross-site scripting, SQL injection, code injection, improper access control, and cross-site request forgery—signature flaws in web-facing business software that can lead to data compromise, privilege escalation, and system takeover. Defenders deploying Dolibarr should treat updates as high-priority, restrict internet exposure where feasible, and implement compensating controls such as web application firewalls; current severity, exploitation, and public-exploit counts are shown alongside this summary.

FAUCET AI Generated
140
Total CVEs
More Total CVEs than 99% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
7.3
Avg CVSS Score
Higher Avg CVSS Score than 55% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Dolibarr over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 28, 2011
14 years ago
Most Recent CVE
Jun 30, 2026
24 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (140 CVEs).

140 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2018-10094CRITICAL
SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.
May 22, 20189.885NOYES
CVE-2023-30253HIGH
Dolibarr before 17.0.1 allows remote code execution by an authenticated user via an uppercase manipulation: <?PHP instead of <?php in injected data.
May 29, 20238.880NOYES
CVE-2018-10095MEDIUM
Cross-site scripting (XSS) vulnerability in Dolibarr before 7.0.2 allows remote attackers to inject arbitrary web script or HTML via the foruserlogin parameter to adherents/cartes/
May 22, 20186.176NOYES
CVE-2021-33618MEDIUM
Dolibarr ERP and CRM 13.0.2 allows XSS via object details, as demonstrated by > and < characters in the onpointermove attribute of a BODY element to the user-management feature.
Nov 10, 20216.164NONO
CVE-2024-5315CRITICAL
Vulnerabilities in Dolibarr ERP - CRM that affect version 9.0.1 and allow SQL injection. These vulnerabilities could allow a remote attacker to send a specially crafted SQL query t
May 24, 20249.156NOYES
CVE-2012-1226HIGH
Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files and possibly execute arbitrary code via a .. (dot dot) in th
Feb 21, 20127.554NOYES
CVE-2022-0819HIGH
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
Mar 2, 20228.852NONO
CVE-2020-14209HIGH
Dolibarr before 11.0.5 allows low-privilege users to upload files of dangerous types, leading to arbitrary code execution. This occurs because .pht and .phar files can be uploaded.
Sep 2, 20208.852NOYES
CVE-2022-40871CRITICAL
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious c
Oct 12, 20229.849NONO
CVE-2023-33568HIGH
An issue in Dolibarr 16 before 16.0.5 allows unauthenticated attackers to perform a database dump and access a company's entire customer file, prospects, suppliers, and employee in
Jun 13, 20237.548NOYES
View all 140 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products140 CVEs
47%
29%
24%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network129 (92.1%)
Unknown9 (6.4%)
Physical1 (0.7%)
Adjacent Network1 (0.7%)
Attack Complexity
Low130 (92.9%)
High1 (0.7%)
Unknown9 (6.4%)
User Interaction
None73 (52.1%)
Unknown9 (6.4%)
Required58 (41.4%)
Privileges Required
Low62 (44.3%)
High8 (5.7%)
None61 (43.6%)
Unknown9 (6.4%)

Exploit Exposure

Signals from CVEs in this vendor scope (140 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
3 CVEs
2.1% of CVEs· 97th percentile
Nuclei
4 CVEs
2.9% of CVEs· 95th percentile
ExploitDB
10 CVEs
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Dolibarr.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Dolibarr — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Dolibarr's Products

View all 9 CNAs →

Top CWEs