In Dolibarr versions up to 21.0.4, 22.0.5, and 23.0.3 a medium severity vulnerability CVE-2026-85401 was detected. This vulnerability allows a remote attacker to bypass access restrictions, potentially leading to unauthorized access, modification, or disclosure of sensitive files. This occurs due to an improper access control flaw within the htdocs/core/filemanagerdol/connectors/php/config.inc.php file of the Legacy File Manager component. Warning: A public exploit for this vulnerability is available and could be used in active attacks. To address this issue, users should upgrade Dolibarr to version 23.0.4 or later, or apply the official patch (commit ef6631e9bd5ec4b8cec0e88f1796d3d10dad02ec). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-85401.
In Dolibarr versions up to 23.0.4 a medium severity vulnerability CVE-2026-77686 was detected. This vulnerability allows a remote attacker to bypass authorization checks, potentially leading to unauthorized access or modification of account details. This occurs due to an improper authorization flaw within the Account Handler component, specifically in the htdocs/user/card.php file. By manipulating the ID argument in the request, an attacker can access or alter resources belonging to other users. Warning: A public exploit for this vulnerability is available and could be used in active attacks. To address this issue, users should upgrade Dolibarr to version 24.0.0 or later, or apply the official patch (commit b2a2c995537cb6282383b5e903cb5ffa29b823e6). For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-77686.
In Dolibarr ERP & CRM versions up to and including 21.0.1 a high severity vulnerability CVE-2025-56588 was detected. This vulnerability allows an authenticated attacker to execute arbitrary code on the underlying server, leading to Remote Code Execution (RCE). This occurs due to insecure processing of the computed field parameter within the User module configuration. By injecting malicious payloads into this configuration field, an attacker can bypass intended restrictions and run arbitrary system commands. To address this issue, users should upgrade Dolibarr ERP & CRM to a patched version version 21.0.3 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-56588.
Read more ERPIn Dolibarr ERP & CRM versions up to and including 22.0.4 a high severity vulnerability CVE-2026-31018 was detected. This vulnerability allows an authenticated user with restricted privileges (limited to HTML/JavaScript editing) to inject and execute arbitrary PHP code, potentially leading to Remote Code Execution (RCE) and privilege escalation. This occurs due to the inconsistent application of PHP code detection and permission enforcement within the Website module. During website page creation, certain input parameters remain unprotected, allowing an attacker to bypass intended restrictions and supply malicious PHP payloads. To address this issue, users should upgrade Dolibarr to a patched version 23.0.0 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-31018.
Read more ERPIn Dolibarr ERP/CRM version 6.0.0 a medium severity vulnerability CVE-2017-14240 was detected. This vulnerability allows attackers to access sensitive information due to a flaw in the document.php file via the file parameter. To address this issue, users should upgrade Dolibarr ERP/CRM to version 6.0.1 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-14240.
Read more ERPIn Dolibarr ERP/CRM versions before 5.0.3 a high severity vulnerability CVE-2017-9435 was detected. This vulnerability allows attackers to execute arbitrary SQL commands due to a SQL injection flaw in the search_supervisor and search_statut parameters within the user/index.php file. To address this issue, users should upgrade Dolibarr ERP/CRM to version 5.0.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2017-9435.
Read more ERPIn Dolibarr ERP/CRM version 3.8.3 a low severity vulnerability CVE-2016-1912 was detected. This vulnerability allows remote authenticated users to inject arbitrary web script or HTML via the lastname, firstname, email, job, or signature parameters to htdocs/user/card.php, leading to Cross-Site Scripting (XSS). To address this issue, users should upgrade Dolibarr ERP/CRM to versions 3.8.3 or higher. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2016-1912.
Read more ERPIn Dolibarr versions prior to 23.0.0 a critical severity vulnerability CVE-2026-23500 was detected. This vulnerability allows authenticated administrators to inject arbitrary OS commands and achieve remote code execution (RCE) as the web server user by manipulating the MAIN_ODT_AS_PDF configuration constant during the ODT to PDF conversion process. To address this issue, users should upgrade Dolibarr to version 23.0.0. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-23500.
Read more ERPIn Dolibarr ERP/CRM versions prior to 23.0.2 a high vulnerability CVE-2026-22666 allows authenticated administrators to achieve remote code execution through the dol_eval_standard() function. The function fails to properly enforce forbidden string checks in whitelist mode and does not detect PHP dynamic callable syntax, allowing attackers to inject malicious payloads via computed extrafields or other evaluation paths. To address this issue, users should upgrade Dolibarr to version 23.0.2. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-22666.
Read more ERP