Dolibarr ERP & CRM是Dolibarr开源的一个企业管理软件。 Dolibarr ERP & CRM 22.0.4及之前版本存在安全漏洞,该漏洞源于网站模块使用基于黑名单的过滤来限制危险的PHP函数,允许具有PHP内容编辑权限的认证用户绕过过滤,导致完全远程代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6744 | 6.3 MEDIUM | Bagisto Downloadable Link copy server-side request forgery |
| CVE-2026-6745 | 3.5 LOW | Bagisto Custom Scripts cross site scripting |
| CVE-2026-29644 | XiangShan 安全漏洞 | |
| CVE-2026-31018 | Dolibarr ERP & CRM 安全漏洞 | |
| CVE-2026-31014 | Infoopia Dovestones AD Self Update 安全漏洞 | |
| CVE-2026-31013 | Infoopia Dovestones ADPhonebook 安全漏洞 | |
| CVE-2026-37748 | Visitor Management System 安全漏洞 | |
| CVE-2026-38834 | Tenda W30E 安全漏洞 | |
| CVE-2026-38835 | Tenda W30E 安全漏洞 | |
| CVE-2026-30452 | Textpattern CMS 安全漏洞 |
No comments yet