Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Group: vendors Tag: dolibarr-erpcrm Clear
ID Title
CVE-2025-67486 Vulnerability in dolibarr (CVE-2025-67486)
vulnerability in dolibarr (CVE-2025-67486). Successful exploitation can lead to full system takeover.
CVE-2017-17971 Cross-Site Scripting (XSS) in dolibarr (CVE-2017-17971)
cross-site scripting in dolibarr (CVE-2017-17971). Risk of unauthorized operations or information disclosure.
CVE-2017-17900 SQL Injection in sqli (CVE-2017-17900)
SQL injection in sqli (CVE-2017-17900). Successful exploitation can lead to full system takeover.
CVE-2017-17897 SQL Injection in sqli (CVE-2017-17897)
SQL injection in sqli (CVE-2017-17897). Successful exploitation can lead to full system takeover.
CVE-2017-17898 Information Disclosure in dolibarr (CVE-2017-17898)
vulnerability in dolibarr (CVE-2017-17898). Confidential information can be exposed externally.
CVE-2017-17899 SQL Injection in sqli (CVE-2017-17899)
SQL injection in sqli (CVE-2017-17899). Successful exploitation can lead to full system takeover.
CVE-2017-7886 Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.
Dolibarr ERP/CRM 4.0.4 has SQL Injection in doli/theme/eldy/style.css.php via the lang parameter.
CVE-2017-7887 Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.
Dolibarr ERP/CRM 4.0.4 has XSS in doli/societe/list.php via the sall parameter.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →