Browse all 34 CVE security advisories affecting dolibarr. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Dolibarr is an open-source Enterprise Resource Planning and Customer Relationship Management system designed for businesses, foundations, and freelancers to manage invoices, inventory, and contacts. Historically, its codebase has exhibited vulnerabilities typical of PHP-based web applications, including SQL injection, cross-site scripting, and insecure direct object references. Notable issues have involved remote code execution and privilege escalation, often stemming from insufficient input validation or improper access control mechanisms. While the project maintains an active development cycle, the accumulation of thirty-three Common Vulnerabilities and Exposures highlights the challenges of securing complex, community-driven software. Recent patches have addressed critical flaws allowing unauthorized data access or system compromise. Users are advised to maintain strict update protocols and implement robust network segmentation to mitigate risks associated with these historically common vulnerability classes within the platform.
GHSA-hh5p-m24x-fwx22026-04-07CVE-2025-696342026-02-13Showing up to 20 recent security advisories. View all →
This page lists every published CVE security advisory associated with dolibarr. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.