Dolibarr

7 known vulnerabilities in Dolibarr, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-89013 CVSS 8.7 high Dolibarr 23.0.4 before 24.0.1 contains an authorization bypass vulnerability that allows unauthenticated attackers to read arbitrary files…
  • CVE-2026-89012 CVSS 7.1 high Dolibarr 24.0.0 before 24.0.1 contains a case-sensitive denylist bypass vulnerability in the sqlfilters API query parameter that allows…
  • CVE-2026-85401 CVSS 2.1 low A weakness has been identified in Dolibarr up to 21.0.4/22.0.5/23.0.3. Affected by this issue is some unknown functionality of the file…
  • CVE-2026-82633 CVSS 5.3 medium Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing…
  • CVE-2026-81730 CVSS 8.8 high Dolibarr 9.0.0 through 23.0.4 saves inbound email attachments under the name supplied in the message's MIME headers without reducing it to…
  • CVE-2026-81729 CVSS 7.1 high Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in…
  • CVE-2026-81728 CVSS 8.6 high Dolibarr before 24.0.0 contains a SQL injection in its CSV and XLSX import wizard. The wizard reads its update keys with…