Advanced Project Status

Generated on 2026-09-15 02:35:37 in 2127 seconds by apstats

Lines of code

LanguageBytesFilesLinesBlanksCommentsCode (SLOC)
All files without dependencies    
See detail per file type...
04 1091 776 681201 876360 3661 214 439
All files of dependencies only    
See detail per file type...
03 384827 90973 461167 853586 595
Total07 4932 604 590275 337528 2191 801 034

Contributions

Pushes and Commits of Dolibarr/dolibarr Pull Request Size of Dolibarr/dolibarr

Contributors


Thumbs of most active contributors

Dolibarr


Star History of Dolibarr/dolibarr

Project value

COCOMO value
(Basic/Semi-detached model)
$138 741 556
COCOMO effort
(Basic/Semi-detached model)
12 133 months people

Last security issues (last 6 months)

Commit IDDateReported on a
VDP (GHSA, Yogosha...)
Reported on
GitHub issues
Reported on
CVE
TitleBranch of fix
3c85c0a3… 2026-09-14#40330SEC: IDOR in order/proposal/invoice line update API (558292601) (#40330) (#40411), SEC: IDOR in order/proposal/invoice line update API (558292601) (#40330) (#40412), SEC: IDOR in order/proposal/invoice line update API (558292601) (#40330)18.0, 22.0, 24.0, develop
2db00d08… 2026-09-14#40340SEC: Check access to source order in getOrderShipments/createOrderShipment (#40340) (#40413), SEC: Check access to source order in getOrderShipments/createOrderShipment (#40340) (#40414), SEC: Check access to source order in getOrderShipments/createOrderShipment (#40340)18.0, 22.0, 23.0
e4825583… 2026-09-14#40313SEC: IDOR in salary AJAX endpoint bypasses read scope permissions (558292493) (#40313) (#40415), SEC: IDOR in salary AJAX endpoint bypasses read scope permissions (558292493) (#40313)22.0, 24.0, develop
ed441bc4…2026-09-14#40409SEC: Any users with "Delete or disable other users" permission can (#40409)22.0
1bf04178… 2026-09-14#40410CVE-2026-89013Fix incomplete remediation of CVE-2026-89013 in website wrapper.php (#40410), Fix incomplete remediation of CVE-2026-89013 in website wrapper.php22.0, 24.0, develop
0a72dfbf…2026-09-14#40406CVE-2026-77923Fix authorization bypass in clonetasks mass action (CVE-2026-77923 bypass) (#40406)24.0, develop
e2dfb13d…2026-09-12#39393SEC: port the AI assistant CRUD/CSRF hardening of #39393 (24.0) to develop (#40359)develop
5cfd8ba9…2026-09-11SEC: Any users with "Delete or disable other users" permission can delete admin account (558292494) - reported Google and Ada Logics24.0, develop
84bd0322…2026-09-09#39288Sec: Fix potential injection with cast to int (timespent_duration) (#39288)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
01996810…2026-09-08#40161SEC: Update security{,2}.lib for strlen usage (#40161)develop
f7d677e4…2026-09-07SEC: A user must also be admin to use the permission create/run scheduled job - reported by Nguyen Viet Tin24.0, develop
e01a12ff…2026-08-09CVE-2026-71506--Fix CVE-2026-71506 - test on permission to delete payment in api24.0, develop
12687f83…2026-08-09CVE-2026-71510Fix CVE-2026-71510 forgeSQLFromUniversalSearchCriteria must disallow some search criteria24.0, develop
f551727d…2026-07-27#39286Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)24.0, develop
7b45ae06…2026-07-24Clean code and comment to fix sec pruposes24.0, develop
9926334e…2026-07-23#39234Sec: sql injection via api in POST of thirdparties/id/banckaccount - (#39234)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
7ec00338…2026-07-20#3923522 report sec (#39235)22.0, 23.0, 24.0, develop
61916b90…2026-07-18Sec: Fix wrong test on salary id - reported by Arpit Jain24.0, develop
1057ad6c… 2026-07-18Sec: sql injection via api in POST of thirdparties/id/banckaccount - reported by MDnyn23.0, 24.0, develop
24b1b99c…2026-07-10Sec possible injection during import - reported by Michael Holmquist (Hasplabs)24.0, develop
ee9377f4…2026-06-28#39000SEC #39000 Escalation to admin when user has clone permission - credit Abderrahmane Aksoum on the fix commit24.0, develop
b726e3b8… 2026-06-23#38942SEC: Sanitize SQL query parameters (#38942) (#38955), SEC: Sanitize SQL query parameters (#38942)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
957f117d…2026-06-21#38941SEC: Fix SQL injection vulnerability in contract list (#38941)21.0, 22.0, 23.0, 24.0, develop
edcde65d…2026-06-21#38943SEC: Correct SQL escaping for signed_status (#38943)21.0, 22.0, 23.0, 24.0, develop
2126f231…2026-04-30SEC: Advisory for bbbbb56c6455514dcd0acca53afc17a92ed21bb9 - Better sanitization param for GETPOST of htmlheader of website page23.0, 24.0, develop
bc249547… 2026-04-23#ghsa-8qh8-6h88-q46p#37973Fix fatal error on customreports, regression #GHSA-8qh8-6h88-q46p (#37973), FIX #GHSA-8qh8-6h88-q46p23.0, 24.0, develop
17265d86… 2026-04-20#ghsa-hq5j-39f9-qxcv#37812FIX #GHSA-hq5j-39f9-qxcv (#37812), FIX #GHSA-hq5j-39f9-qxcv, FIX #GHSA-hq5j-39f9-qxcv18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
ad9328ec… 2026-04-09#ghsa-crgg-h74r-2m8r#37636FIX #GHSA-crgg-h74r-2m8r (#37636), FIX #GHSA-crgg-h74r-2m8r (#37637)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
9533677c…2026-04-03#ghsa-prg3-w5r4-h7g3FIX #GHSA-prg3-w5r4-h7g323.0, 24.0, develop
ee8ded7c…2026-03-29#ghsa-5cfw-655w-vqp8Fix #GHSA-5cfw-655w-vqp823.0, 24.0, develop
7113794c…2026-03-29#ghsa-7mvq-p95c-38fxFix #GHSA-7mvq-p95c-38fx23.0, 24.0, develop
e263a85f…2026-03-26#ghsa-ph29-326p-chw4FIX #GHSA-ph29-326p-chw4 - disable+sanitize deprecated load/save files23.0, 24.0, develop
fb251fee… 2026-03-26#ghsa-39vm-9q4p-6jjg#37629FIX #GHSA-39vm-9q4p-6jjg - force disabling module possible on demo only (#37629), FIX #GHSA-39vm-9q4p-6jjg - force disabling module possible on demo only22.0, 23.0, 24.0, develop
1f1b6bf4… 2026-03-26#ghsa-hh5p-m24x-fwx2#37630FIX #GHSA-hh5p-m24x-fwx2 block ssrf when using webhooks (#37630), FIX #GHSA-hh5p-m24x-fwx2 block ssrf when using webhooks22.0, 23.0, 24.0, develop
c83c1330… 2026-03-26#ghsa-v5fq-cf5m-vwv7#37632FIX #GHSA-v5fq-cf5m-vwv7 - Credit Grzegorz Tworek, Sec4check (#37632), FIX #GHSA-v5fq-cf5m-vwv7 - Credit Grzegorz Tworek, Sec4check (grzegorz.tworek@sec4check.pl)22.0, 23.0, 24.0, develop
11244390… 2026-03-26#ghsa-qjj8-wpvx-p54jFIX #GHSA-qjj8-wpvx-p54j - test on hierarchy not done on some api23.0, 24.0, develop
18aa4442… 2026-03-26#ghsa-5jmx-352f-p5g3NEW use of rich editor is off by default on public page - #GHSA-5jmx-352f-p5g3, NEW Start implementation of MAIN_RESTRICTHTML_ONLY_VALID_HTML=2 for #GHSA-5jmx-352f-p5g324.0, develop
67e35e3f…2026-03-26#ghsa-jc53-p98m-66wvFix #GHSA-jc53-p98m-66wv - SSRF better on servers with ipv6 only24.0, develop
6d68a68b…2026-03-26#ghsa-5w4f-94xq-w36fFix #GHSA-5w4f-94xq-w36f - wrapper to download files in public ticket is too open24.0, develop
f98e60bd… 2026-03-25#ghsa-7hqv-pvw6-cw54FIX #GHSA-7hqv-pvw6-cw5423.0, 24.0, develop
ea1d3605…2026-03-25#ghsa-3g6r-h9mx-5gg9FIX #GHSA-3g6r-h9mx-5gg924.0, develop
6f425521…2026-03-25#ghsa-vmvw-qq8w-wqhgFIx #GHSA-vmvw-qq8w-wqhg23.0, 24.0, develop
29c63752…2026-03-25#ghsa-mh66-3w5r-xg9jFix #GHSA-mh66-3w5r-xg9j23.0, 24.0, develop
8ab83f3b…2026-03-25#ghsa-3j3p-jjf7-hm9gBackport fix #GHSA-3j3p-jjf7-hm9g22.0, 23.0, 24.0, develop

Note:Search is done in git repository on regex string "#ghsa|#yogosha|CVE[\s\-]*\d|Sec:|Sec |^Sec\s" (not case sensitive)
You can use this URL for RSS notifications: index-security.rss

Technical debt (PHPStan - PHP Static Analysis Tool 1.12.33 - level 9 -> 98 warnings)

FileLineType
htdocs/core/lib/project.lib.php3018Variable $progressCalculated in isset() always exists and is not nullable.
htdocs/core/menus/standard/auguria.lib.php599Offset 'mainmenu' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/auguria.lib.php602Offset 'mainmenu' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/auguria.lib.php623Offset 'prefix' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/auguria.lib.php644Offset 'prefix' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/auguria.lib.php696Offset 'level' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/auguria_menu.php217Offset 'prefix' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/auguria_menu.php359Offset 'prefix' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/eldy_menu.php217Offset 'prefix' on array{url: mixed} in empty() does not exist.
htdocs/core/menus/standard/eldy_menu.php351Offset 'prefix' on array{url: mixed} in empty() does not exist.
htdocs/core/modules/facture/doc/doc_generic_invoice_odt.modules.php338Variable $array_propal_object in isset() always exists and is not nullable.
htdocs/core/modules/facture/modules_facture.php193Call to static method create() on an unknown class Sprain\SwissQrBill\QrBill.
htdocs/core/modules/facture/modules_facture.php196Call to static method create() on an unknown class Sprain\SwissQrBill\DataGroup\Element\CombinedAddress.
htdocs/core/modules/facture/modules_facture.php211Call to static method create() on an unknown class Sprain\SwissQrBill\DataGroup\Element\CreditorInformation.
htdocs/core/modules/facture/modules_facture.php227Call to static method create() on an unknown class Sprain\SwissQrBill\DataGroup\Element\PaymentReference.
htdocs/core/modules/facture/modules_facture.php228Access to constant TYPE_NON on an unknown class Sprain\SwissQrBill\DataGroup\Element\PaymentReference.
htdocs/core/modules/facture/modules_facture.php235Call to static method create() on an unknown class Sprain\SwissQrBill\DataGroup\Element\PaymentAmountInformation.
htdocs/core/modules/facture/modules_facture.php244Call to static method create() on an unknown class Sprain\SwissQrBill\DataGroup\Element\AdditionalInformation.
htdocs/core/modules/facture/modules_facture.php251Call to static method create() on an unknown class Sprain\SwissQrBill\DataGroup\Element\CombinedAddress.
htdocs/core/modules/facture/modules_facture.php314Instantiated class Sprain\SwissQrBill\PaymentPart\Output\TcPdfOutput\TcPdfOutput not found.

Technical debt (Phan 5.5.2 -> 468 warnings)

FileLineDetail
htdocs/blockedlog/admin/filecheck.php534Plugin FunctionMissingSingleQuoteWrapping Function dol_escape_js($langs->trans('Loading').'...') output must be wrapped in single quotes
htdocs/compta/tva/clients.php329TypeError PhanTypeArraySuspiciousNull Suspicious array access to $x_paye[$my_paye_thirdpartyid]['pstatus'] of type null
htdocs/compta/tva/clients.php329TypeError PhanTypeInvalidDimOffset Invalid offset "pstatus" of $x_paye[$my_paye_thirdpartyid] of array type array{totalht:float,vat:float,localtax1:float,localtax2:float,dtotal_ttc:float[],dtype:int[],datef:int[],datep:int[],company_name:string[],company_id:int[],company_alias:string[],company_email:string[],company_tva_intra:string[],company_client:int[],company_fournisseur:int[],company_customer_code:string[],company_supplier_code:string[],company_customer_accounting_code:string[],company_supplier_accounting_code:string[],company_status:int[],user_id:int[],drate:string[],ddate_start:int[],ddate_end:int[],facid:int[],facnum:string[],type:int[],ftotal_ttc:float[],descr:string[],totalht_list:string[],vat_list:float[],localtax1_list:float[],localtax2_list:float[],pid:int[],pref:string[],ptype:int[],payment_id:int[],payment_ref:string[],payment_amount:float[]}
htdocs/compta/tva/clients.php330TypeError PhanTypeArraySuspiciousNull Suspicious array access to $x_paye[$my_paye_thirdpartyid]['pstatusbuy'] of type null
htdocs/compta/tva/clients.php330TypeError PhanTypeInvalidDimOffset Invalid offset "pstatusbuy" of $x_paye[$my_paye_thirdpartyid] of array type array{totalht:float,vat:float,localtax1:float,localtax2:float,dtotal_ttc:float[],dtype:int[],datef:int[],datep:int[],company_name:string[],company_id:int[],company_alias:string[],company_email:string[],company_tva_intra:string[],company_client:int[],company_fournisseur:int[],company_customer_code:string[],company_supplier_code:string[],company_customer_accounting_code:string[],company_supplier_accounting_code:string[],company_status:int[],user_id:int[],drate:string[],ddate_start:int[],ddate_end:int[],facid:int[],facnum:string[],type:int[],ftotal_ttc:float[],descr:string[],totalht_list:string[],vat_list:float[],localtax1_list:float[],localtax2_list:float[],pid:int[],pref:string[],ptype:int[],payment_id:int[],payment_ref:string[],payment_amount:float[]}
htdocs/compta/tva/clients.php371TypeError PhanTypeArraySuspiciousNull Suspicious array access to $x_paye[$my_paye_thirdpartyid]['pstatus'] of type null
htdocs/compta/tva/clients.php371TypeError PhanTypeInvalidDimOffset Invalid offset "pstatus" of $x_paye[$my_paye_thirdpartyid] of array type array{totalht:float,vat:float,localtax1:float,localtax2:float,dtotal_ttc:float[],dtype:int[],datef:int[],datep:int[],company_name:string[],company_id:int[],company_alias:string[],company_email:string[],company_tva_intra:string[],company_client:int[],company_fournisseur:int[],company_customer_code:string[],company_supplier_code:string[],company_customer_accounting_code:string[],company_supplier_accounting_code:string[],company_status:int[],user_id:int[],drate:string[],ddate_start:int[],ddate_end:int[],facid:int[],facnum:string[],type:int[],ftotal_ttc:float[],descr:string[],totalht_list:string[],vat_list:float[],localtax1_list:float[],localtax2_list:float[],pid:int[],pref:string[],ptype:int[],payment_id:int[],payment_ref:string[],payment_amount:float[]}
htdocs/compta/tva/clients.php372TypeError PhanTypeArraySuspiciousNull Suspicious array access to $x_paye[$my_paye_thirdpartyid]['pstatusbuy'] of type null
htdocs/compta/tva/clients.php372TypeError PhanTypeInvalidDimOffset Invalid offset "pstatusbuy" of $x_paye[$my_paye_thirdpartyid] of array type array{totalht:float,vat:float,localtax1:float,localtax2:float,dtotal_ttc:float[],dtype:int[],datef:int[],datep:int[],company_name:string[],company_id:int[],company_alias:string[],company_email:string[],company_tva_intra:string[],company_client:int[],company_fournisseur:int[],company_customer_code:string[],company_supplier_code:string[],company_customer_accounting_code:string[],company_supplier_accounting_code:string[],company_status:int[],user_id:int[],drate:string[],ddate_start:int[],ddate_end:int[],facid:int[],facnum:string[],type:int[],ftotal_ttc:float[],descr:string[],totalht_list:string[],vat_list:float[],localtax1_list:float[],localtax2_list:float[],pid:int[],pref:string[],ptype:int[],payment_id:int[],payment_ref:string[],payment_amount:float[]}
htdocs/core/actions_addupdatedelete.inc.php158UndefError PhanUndeclaredProperty Reference to undeclared property \CommonObject->param_list
htdocs/core/actions_addupdatedelete.inc.php324UndefError PhanUndeclaredProperty Reference to undeclared property \CommonObject->param_list
htdocs/core/actions_massactions.inc.php187UndefError PhanUndeclaredProperty Reference to undeclared property \CommonObject->socid
htdocs/core/actions_sendmails.inc.php168UndefError PhanUndeclaredProperty Reference to undeclared property \ExpenseReport->socid
htdocs/core/actions_sendmails.inc.php169UndefError PhanUndeclaredProperty Reference to undeclared property \ExpenseReport->socid
htdocs/core/ajax/ajaxdirtree.php435TypeError PhanTypeMismatchArgument Argument 1 ($fulltree) is $sqltree of type array but \tree_showpad() takes array defined at htdocs/core/lib/treeview.lib.php:37
htdocs/core/class/CMailFile.class.php589TypeError PhanTypeMismatchArgument Argument 1 ($_strReferences) is $this->references of type non-empty-string but \SMTPs::setReferences() takes string[] defined at htdocs/core/class/smtps.class.php:1242
htdocs/core/class/canvas.class.php255UndefError PhanUndeclaredMethod Call to undeclared method \ActionsContactCardCommon::doActions
htdocs/core/class/cgenericdic.class.php460UndefError PhanUndeclaredProperty Reference to undeclared property \CGenericDic->context
htdocs/core/class/cgenericdic.class.php470UndefError PhanUndeclaredProperty Reference to undeclared property \CGenericDic->context
htdocs/core/class/commonpeople.class.php115UndefError PhanUndeclaredProperty Reference to undeclared property \CommonPeople->societe