Advanced Project Status

Generated on 2026-09-30 00:25:14 in 1500 seconds by apstats

Lines of code

LanguageBytesFilesLinesBlanksCommentsCode (SLOC)
All files without dependencies    
See detail per file type...
04 0961 746 451202 115363 0011 181 335
All files of dependencies only    
See detail per file type...
03 385828 37973 551167 910586 918
Total07 4812 574 830275 666530 9111 768 253

Contributions

Pull Request Size of Dolibarr/dolibarr

Contributors


Thumbs of most active contributors

Dolibarr


Star History of Dolibarr/dolibarr

Project value

COCOMO value
(Basic/Semi-detached model)
$135 836 521
COCOMO effort
(Basic/Semi-detached model)
11 816 months people

Last security issues (last 6 months)

Commit IDDateReported on a
VDP (GHSA, Yogosha...)
Reported on
GitHub issues
Reported on
CVE
TitleBranch of fix
1d780d4c…2026-09-29#41064SEC: subscription card acted on a subscription of another entity by id (#41064)20.0, 21.0
c84f7205…2026-09-29#41065SEC: various payment card acted on a payment of another entity by id (#41065)20.0, 21.0
59860897…2026-09-29#41019SEC: societe/paymentmodes.php acted on bank accounts of any company by id (#41019)21.0
32a20f24…2026-09-29#41021SEC: comm/remx.php split/removed a discount of any other company by id (#41021)23.0
75e43781…2026-09-29#41023SEC: a credit note/discount of any company could be applied to an invoice (#41023)20.0, 21.0
1d73622e…2026-09-29#41024SEC: invoice card deleted a payment / unlinked a credit note of another invoice (#41024)20.0, 21.0
d487cf85…2026-09-29#41066SEC: loan payment card had no access check (any entity, no read right) (#41066)20.0, 21.0
a478ae91… 2026-09-29#40994SEC: deleteLine() deleted a line of any other object (#40994) (#41050), SEC: deleteLine() deleted a line of any other object (#40994)22.0, 23.0, 24.0, develop
b1d7d921…2026-09-29#41079SEC: dellink action deletes any object link by rowid (#41079)20.0, 21.0, 22.0, 23.0, 24.0, develop
caf20f1a… 2026-09-29#40998Revert "SEC: object-link delete by rowid was not scoped to the object (#40998)" (#41068), SEC: object-link delete by rowid was not scoped to the object (#40998)23.0, 24.0, develop
156874d5…2026-09-29#40995SEC: updateline() modified a line of any other object (#40995)23.0, 24.0, develop
720bcd9d…2026-09-28#40997SEC: line reorder rewrote the rang of a line of any other object (#40997)23.0, 24.0, develop
a119693a…2026-09-28#40993SEC: Project overview link/unlink trusted posted table, column and row (#40993)23.0, 24.0, develop
2260f0d0…2026-09-28#40992SEC: resource links of another element can be updated or deleted (#40992)23.0, 24.0, develop
b2757206…2026-09-28#40991SEC: CommonObject::delete_contact() removes a contact link of any object (#40991)23.0, 24.0, develop
e04106f8…2026-09-28#40988SEC: dispatch pages update or delete lines of another shipment, reception or purchase order (#40988)23.0, 24.0, develop
0d308d50…2026-09-28#40984SEC: user API token pages act on tokens of other users (#40984)23.0, 24.0, develop
a3fbb452…2026-09-28#40982SEC: notify_def delete by rowid alone, not scoped to the current thirdparty/user (#40982)23.0, 24.0, develop
e64820ec… 2026-09-28#40797SEC: TakePOS order printers setup was open to any user able to read categories (#40797) (#40976), SEC: TakePOS order printers setup was open to any user able to read categories (#40797)22.0, 23.0, 24.0, develop
90430c27… 2026-09-28#40816SEC: TakePOS could send or print the receipt of any invoice, of any entity (#40816) (#40974), SEC: TakePOS could send or print the receipt of any invoice, of any entity (#40816)22.0, 23.0, 24.0, develop
3c055dcc…2026-09-26#40815SEC: supplier recap of any third party readable by a user restricted to his own customers (#40815)23.0, 24.0, develop
c4e2c9f8…2026-09-26#40763SEC: getURLContent() must not forward credentials on a redirection to another host (#40763)develop
d00cef89…2026-09-25#40817SEC: mass actions must check the user can access each selected object (#40817)develop
d5d70a5a…2026-09-25#40778SEC: pingresult.php computes the instance hash itself and requires the token (#40778)develop
ab2b0dd3…2026-09-20#40579SEC AI: mask the API key in logged provider URLs (#40579)develop
cd16a53f…2026-09-18#40520SEC AI assistant: Enforce per-tool Dolibarr rights on every MCP tool call (#40520)develop
3c85c0a3… 2026-09-14#40330SEC: IDOR in order/proposal/invoice line update API (558292601) (#40330) (#40411), SEC: IDOR in order/proposal/invoice line update API (558292601) (#40330) (#40412), SEC: IDOR in order/proposal/invoice line update API (558292601) (#40330)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
2db00d08… 2026-09-14#40340SEC: Check access to source order in getOrderShipments/createOrderShipment (#40340) (#40413), SEC: Check access to source order in getOrderShipments/createOrderShipment (#40340) (#40414), SEC: Check access to source order in getOrderShipments/createOrderShipment (#40340)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
e4825583… 2026-09-14#40313SEC: IDOR in salary AJAX endpoint bypasses read scope permissions (558292493) (#40313) (#40415), SEC: IDOR in salary AJAX endpoint bypasses read scope permissions (558292493) (#40313)22.0, 23.0, 24.0, develop
ed441bc4…2026-09-14#40409SEC: Any users with "Delete or disable other users" permission can (#40409)22.0, 23.0, 24.0, develop
1bf04178… 2026-09-14#40410CVE-2026-89013Fix incomplete remediation of CVE-2026-89013 in website wrapper.php (#40410), Fix incomplete remediation of CVE-2026-89013 in website wrapper.php22.0, 23.0, 24.0, develop
0a72dfbf…2026-09-14#40406CVE-2026-77923Fix authorization bypass in clonetasks mass action (CVE-2026-77923 bypass) (#40406)24.0, develop
e2dfb13d…2026-09-12#39393SEC: port the AI assistant CRUD/CSRF hardening of #39393 (24.0) to develop (#40359)develop
5cfd8ba9…2026-09-11SEC: Any users with "Delete or disable other users" permission can delete admin account (558292494) - reported Google and Ada Logics24.0, develop
84bd0322…2026-09-09#39288Sec: Fix potential injection with cast to int (timespent_duration) (#39288)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
01996810…2026-09-08#40161SEC: Update security{,2}.lib for strlen usage (#40161)develop
f7d677e4…2026-09-07SEC: A user must also be admin to use the permission create/run scheduled job - reported by Nguyen Viet Tin24.0, develop
e01a12ff…2026-08-09CVE-2026-71506--Fix CVE-2026-71506 - test on permission to delete payment in api24.0, develop
12687f83…2026-08-09CVE-2026-71510Fix CVE-2026-71510 forgeSQLFromUniversalSearchCriteria must disallow some search criteria24.0, develop
f551727d…2026-07-27#39286Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)24.0, develop
7b45ae06…2026-07-24Clean code and comment to fix sec pruposes24.0, develop
9926334e…2026-07-23#39234Sec: sql injection via api in POST of thirdparties/id/banckaccount - (#39234)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
7ec00338…2026-07-20#3923522 report sec (#39235)22.0, 23.0, 24.0, develop
61916b90…2026-07-18Sec: Fix wrong test on salary id - reported by Arpit Jain24.0, develop
1057ad6c… 2026-07-18Sec: sql injection via api in POST of thirdparties/id/banckaccount - reported by MDnyn23.0, 24.0, develop
24b1b99c…2026-07-10Sec possible injection during import - reported by Michael Holmquist (Hasplabs)24.0, develop
ee9377f4…2026-06-28#39000SEC #39000 Escalation to admin when user has clone permission - credit Abderrahmane Aksoum on the fix commit24.0, develop
b726e3b8… 2026-06-23#38942SEC: Sanitize SQL query parameters (#38942) (#38955), SEC: Sanitize SQL query parameters (#38942)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
957f117d…2026-06-21#38941SEC: Fix SQL injection vulnerability in contract list (#38941)21.0, 22.0, 23.0, 24.0, develop
edcde65d…2026-06-21#38943SEC: Correct SQL escaping for signed_status (#38943)21.0, 22.0, 23.0, 24.0, develop
2126f231…2026-04-30SEC: Advisory for bbbbb56c6455514dcd0acca53afc17a92ed21bb9 - Better sanitization param for GETPOST of htmlheader of website page23.0, 24.0, develop
bc249547…2026-04-23#ghsa-8qh8-6h88-q46p#37973Fix fatal error on customreports, regression #GHSA-8qh8-6h88-q46p (#37973)23.0, 24.0, develop
17265d86… 2026-04-20#ghsa-hq5j-39f9-qxcv#37812FIX #GHSA-hq5j-39f9-qxcv (#37812), FIX #GHSA-hq5j-39f9-qxcv, FIX #GHSA-hq5j-39f9-qxcv18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
ad9328ec…2026-04-09#ghsa-crgg-h74r-2m8r#37636FIX #GHSA-crgg-h74r-2m8r (#37636)18.0, 19.0, 20.0, 21.0, 22.0, 23.0, 24.0, develop
9533677c…2026-04-03#ghsa-prg3-w5r4-h7g3FIX #GHSA-prg3-w5r4-h7g323.0, 24.0, develop

Note:Search is done in git repository on regex string "#ghsa|#yogosha|CVE[\s\-]*\d|Sec:|Sec |^Sec\s" (not case sensitive)
You can use this URL for RSS notifications: index-security.rss

Technical debt (PHPStan - PHP Static Analysis Tool 2.2.14 - level 9 -> 120 warnings)

FileLineType
htdocs/admin/clicktodial.php172Property Societe::$phone (string) on left side of ?? is not nullable.
htdocs/admin/dict.php2486Strict comparison using !== between mixed and null will always evaluate to true.
htdocs/compta/accounting-files.php767Parameter #1 $array of function dol_sort_array contains unresolvable type.
htdocs/compta/accounting-files.php767Return type of call to function dol_sort_array contains unresolvable type.
htdocs/compta/facture/class/facture.class.php702Parameter #1 $substitutionarray of function complete_substitutions_array expects array, array given.
htdocs/compta/sociales/payments.php184Strict comparison using !== between mixed and null will always evaluate to true.
htdocs/compta/tva/index.php275Strict comparison using === between true and true will always evaluate to true.
htdocs/core/actions_massactions.inc.php1282Parameter #1 $array of function sort contains unresolvable type.
htdocs/core/actions_massactions.inc.php1296Expression "
htdocs/core/ajax/savekanbanfield.php60Function restrictedArea invoked with 10 parameters, 2-9 required.
htdocs/core/ajax/updateextrafield.php84Function restrictedArea invoked with 10 parameters, 2-9 required.
htdocs/core/class/commonobject.class.php3033PHPDoc tag `@var` with type Propal is not subtype of native type $this(CommonObject).
htdocs/core/class/commonobject.class.php3063PHPDoc tag `@var` with type Commande is not subtype of native type $this(CommonObject).
htdocs/core/class/commonobject.class.php3093PHPDoc tag `@var` with type Facture is not subtype of native type $this(CommonObject).
htdocs/core/class/commonobject.class.php3124PHPDoc tag `@var` with type FactureRec is not subtype of native type $this(CommonObject).
htdocs/core/class/commonobject.class.php3157PHPDoc tag `@var` with type SupplierProposal is not subtype of native type $this(CommonObject).
htdocs/core/class/commonobject.class.php3186PHPDoc tag `@var` with type CommandeFournisseur is not subtype of native type $this(CommonObject).
htdocs/core/class/commonobject.class.php3212PHPDoc tag `@var` with type FactureFournisseur is not subtype of native type $this(CommonObject).
htdocs/core/class/fileupload.class.php84Strict comparison using !== between array|string and null will always evaluate to true.
htdocs/core/class/html.form.class.php7156Offset 'datenow' on array{name?: string, value?: bool|float|string, values?: array, default?: string, label?: string, type: 'date'|'datetime', size?: int|string, morecss?: string, ...} in empty() does not exist.

Technical debt (Phan 5.5.2 -> 423 warnings)

FileLineDetail
htdocs/core/actions_addupdatedelete.inc.php153UndefError PhanUndeclaredProperty Reference to undeclared property \CommonObject->param_list
htdocs/core/actions_addupdatedelete.inc.php323UndefError PhanUndeclaredProperty Reference to undeclared property \CommonObject->param_list
htdocs/core/actions_massactions.inc.php200UndefError PhanUndeclaredProperty Reference to undeclared property \CommonObject->socid
htdocs/core/actions_sendmails.inc.php168UndefError PhanUndeclaredProperty Reference to undeclared property \ExpenseReport->socid
htdocs/core/actions_sendmails.inc.php169UndefError PhanUndeclaredProperty Reference to undeclared property \ExpenseReport->socid
htdocs/core/ajax/ajaxdirtree.php435TypeError PhanTypeMismatchArgument Argument 1 ($fulltree) is $sqltree of type array but \tree_showpad() takes array defined at htdocs/core/lib/treeview.lib.php:37
htdocs/core/class/CMailFile.class.php589TypeError PhanTypeMismatchArgument Argument 1 ($_strReferences) is $this->references of type non-empty-string but \SMTPs::setReferences() takes string[] defined at htdocs/core/class/smtps.class.php:1242
htdocs/core/class/canvas.class.php255UndefError PhanUndeclaredMethod Call to undeclared method \ActionsContactCardCommon::doActions
htdocs/core/class/cgenericdic.class.php460UndefError PhanUndeclaredProperty Reference to undeclared property \CGenericDic->context
htdocs/core/class/cgenericdic.class.php470UndefError PhanUndeclaredProperty Reference to undeclared property \CGenericDic->context
htdocs/core/class/commonpeople.class.php115UndefError PhanUndeclaredProperty Reference to undeclared property \CommonPeople->societe
htdocs/core/class/commonpeople.class.php158UndefError PhanUndeclaredProperty Reference to undeclared property \CommonPeople->civilite
htdocs/core/class/commonpeople.class.php158UndefError PhanUndeclaredProperty Reference to undeclared property \CommonPeople->civility
htdocs/core/class/commonpeople.class.php158UndefError PhanUndeclaredProperty Reference to undeclared property \CommonPeople->civility_id
htdocs/core/class/commonpeople.class.php382UndefError PhanUndeclaredProperty Reference to undeclared property \CommonPeople->typent_code
htdocs/core/class/conf.class.php602TypeError PhanTypeMismatchProperty Assigning ($this->modules_parts as a field) of type array to property but \Conf->modules_parts is array
htdocs/core/class/ctyperesource.class.php417UndefError PhanUndeclaredProperty Reference to undeclared property \Ctyperesource->context
htdocs/core/class/ctyperesource.class.php427UndefError PhanUndeclaredProperty Reference to undeclared property \Ctyperesource->context
htdocs/core/class/dolgraph.class.php960UndefError PhanUndeclaredProperty Reference to undeclared property \DolGraph->shownographyet
htdocs/core/class/dolgraph.class.php1272UndefError PhanUndeclaredProperty Reference to undeclared property \DolGraph->shownographyet