Skip to content

Known CVE

Dolibarr <=22.0.4 - Local File Inclusion

Dolibarr <= 22.0.4 contains a local file inclusion caused by manipulation of the objectdesc parameter and a fail-open logic flaw in restrictedArea() in /core/ajax/selectobject.php, letting authenticated users with no specific privileges read arbitrary non-PHP files.

CVE-2026-34036

Medium2026CVSS 6.5CWE-98

cve2026 · dolibarr · lfi · auth · vuln · authenticated

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website