CVE Tools

Dolibarr

61 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Dolibarr, a product in the enterprise software space. Use it to gauge the current risk picture and drill into individual advisories.

Dolibarr CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Dolibarr CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-012
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-020
2026-031
2026-041
2026-051
2026-061
2026-070
2026-0814
2026-092

Severity

How the 61 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1321%
  • High1830%
  • Medium3049%

Latest CVEs

The 15 most recently published vulnerabilities affecting Dolibarr.

  1. CVE-2026-89013Dolibarr 23.0.4 < 24.0.1 Authorization Bypass via hashp Parameter in document.php7.5
  2. CVE-2026-89012Dolibarr 24.0.0 < 24.0.1 SQL Filter Denylist Bypass via sqlfilters Parameter6.5
  3. CVE-2026-82633Dolibarr 10.0.0 before 24.0.0 Missing Authorization on REST Users Groups Endpoint4.3
  4. CVE-2026-81729Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion6.5
  5. CVE-2026-81730Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename8.2
  6. CVE-2026-81728Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys8.1
  7. CVE-2026-77923Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action4.3
  8. CVE-2026-71511Dolibarr < 24.0.0 Members REST API Sensitive Data Exposure via Member Endpoints6.5
  9. CVE-2026-71510Dolibarr < 24.0.0 Users REST API SQL Injection via filter parameter6.5
  10. CVE-2026-71509Dolibarr < 24.0.0 Expense Report REST API Improper Authorization via Update Endpoint6.5
  11. CVE-2026-71508Dolibarr < 24.0.0 REST API Improper Authorization via User Update Endpoint6.5
  12. CVE-2026-71507Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Bank Account Routes6.5
  13. CVE-2026-71506Dolibarr < 24.0.0 Payments REST API Improper Authorization via Delete Endpoint8.1
  14. CVE-2026-71505Dolibarr < 24.0.0 REST API Broken Object-Level Authorization via Third-Party Write Route7.1
  15. CVE-2026-71504Dolibarr < 24.0.0 Members REST API Improper Authorization via Password Reset8.1

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store