Technology · Packagist
dolibarr/dolibarr (Packagist) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 125 vulnerabilities in dolibarr/dolibarr (Packagist): 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-10215, was published on 1 June 2026.
- Last 7 days
- 0
- Last 90 days
- 0
- Critical, all time
- 0
- Exploited in the wild
- 0
About dolibarr/dolibarr (Packagist)
An open-source enterprise resource planning and customer relationship management software suite.
Latest dolibarr/dolibarr (Packagist) vulnerabilities
- CVE-2026-10215: Dolibarr ERP CRM improper authorization in Leave Request REST APImediumCVSS 4.3EPSS 0.3%
- CVE-2026-7689: Dolibarr has Insufficient Verification of Data AuthenticitylowCVSS 3.1EPSS 0.2%
- CVE-2026-7688: Dolibarr ERP CRM SQL injection in Shipments API EndpointmediumCVSS 5EPSS 0.3%
- CVE-2026-31019: Dolibarr ERP & CRM RCE via blacklist bypass in Website modulehighCVSS 8.8EPSS 1.0%
- CVE-2026-31018: Dolibarr ERP & CRM PHP code injection in Website modulehighCVSS 8.8EPSS 0.5%
- CVE-2026-23500: Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configurationlowCVSS 3.1EPSS 0.9%
- CVE-2019-25710: Dolibarr ERP-CRM SQL injection in admin dict.phphighCVSS 8.2EPSS 0.3%
- CVE-2026-34036: Dolibarr Core Discloses Sensitive Data via Authenticated Local File Inclusion in selectobject.phplowCVSS 3.1EPSS 1.5%
- CVE-2025-56588: Dolibarr ERP & CRM remote code execution in User module computed fieldhighCVSS 8.8EPSS 0.5%
- Dolibarr has Remote Code Execution Vulnerability (Bypass)lowCVSS 3.1
- CVE-2024-55228: Dolibarr Cross-site Scripting vulnerabilitylowCVSS 3.1EPSS 0.7%
- CVE-2024-55227: Dolibarr Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 0.6%
- CVE-2021-3991: Improper Authorization in dolibarr/dolibarrlowCVSS 3EPSS 0.3%
- CVE-2024-40137: Dolibarr ERP CRM vulnerable to remote code execution (RCE)lowCVSS 3.1EPSS 0.7%
- CVE-2024-37821: Dolibarr arbitrary file upload vulnerabilitylowCVSS 3.1EPSS 0.8%
- CVE-2024-34051: Reflected Cross-Site Scripting (XSS) in DolibarrinfoEPSS 12.0%
- CVE-2024-5315: Dolibarr vulnerable to SQL InjectionlowCVSS 3.1EPSS 34.5%
- CVE-2024-5314: Dolibarr vulnerable to SQL InjectionlowCVSS 3.1EPSS 0.6%
- CVE-2024-23817: Dolibarr Application Home Page has HTML injection vulnerabilitylowCVSS 3.1EPSS 0.6%
- CVE-2024-31503: Dolibarr vulnerable to Cross-Site Request ForgerylowCVSS 3.1EPSS 0.3%
- CVE-2024-29477: Dolibarr ERP CRM Code Injection vulnerability during installationlowCVSS 3.1EPSS 0.8%
- CVE-2023-4198: Dolibarr Improper Input Validation vulnerabilitylowCVSS 3.1EPSS 0.6%
- CVE-2023-4197: Dolibarr Improper Input Validation vulnerabilitylowCVSS 3.1EPSS 32.9%
- CVE-2023-5842: Cross-site Scripting (XSS) in dolibarr/dolibarrlowCVSS 3.1EPSS 0.5%
- CVE-2023-5323: Dolibarr Cross-site Scripting vulnerabilitylowCVSS 3EPSS 0.4%
Most severe dolibarr/dolibarr (Packagist) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-31019: Dolibarr ERP & CRM RCE via blacklist bypass in Website modulehighCVSS 8.8EPSS 1.0%
- CVE-2026-31018: Dolibarr ERP & CRM PHP code injection in Website modulehighCVSS 8.8EPSS 0.5%
- CVE-2025-56588: Dolibarr ERP & CRM remote code execution in User module computed fieldhighCVSS 8.8EPSS 0.5%
- CVE-2019-25710: Dolibarr ERP-CRM SQL injection in admin dict.phphighCVSS 8.2EPSS 0.3%
- CVE-2026-7688: Dolibarr ERP CRM SQL injection in Shipments API EndpointmediumCVSS 5EPSS 0.3%
- CVE-2026-10215: Dolibarr ERP CRM improper authorization in Leave Request REST APImediumCVSS 4.3EPSS 0.3%
- CVE-2024-55227: Dolibarr Cross-site Scripting vulnerabilitymediumCVSS 4EPSS 0.6%
- CVE-2023-30253: Dolibarr vulnerable to remote code execution via uppercase manipulationlowCVSS 3.1EPSS 82.1%
- CVE-2021-33618: Dolibarr ERP and CRM contain XSS VulnerabilitylowCVSS 3.1EPSS 79.3%
- CVE-2022-0819: Code injection in dolibarr/dolibarrlowCVSS 3.1EPSS 41.0%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/dolibarr-dolibarr.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "dolibarr/dolibarr (Packagist) vulnerabilities", https://junglewise.ai/threats/technologies/dolibarr-dolibarr, 28 September 2026.