CVE-2018-16808: Dolibarr

Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Dolibarr through 7.0.0. There is Stored XSS in expensereport/card.php in the expense reports plugin via the comments parameter, or a public or private note.

Affected products

  • Dolibarr Dolibarr: from 3.8.0, up to and including 7.0.0

Published 2019-03-07. Last modified 2026-06-17.