Known CVE
Dolibarr <=22.0.4 - Local File Inclusion
Dolibarr <= 22.0.4 contains a local file inclusion caused by manipulation of the objectdesc parameter and a fail-open logic flaw in restrictedArea() in /core/ajax/selectobject.php, letting authenticated users with no specific privileges read arbitrary non-PHP files.
CVE-2026-34036
Medium2026CVSS 6.5CWE-98
cve2026 · dolibarr · lfi · auth · vuln · authenticated
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website