dolibarr/htdocs
2026-08-16 06:31:33 +02:00
..
accountancy Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-13 17:48:25 +02:00
adherents Fix(ci): security access check (#39530) 2026-08-15 01:58:01 +02:00
admin Add dolSort to offer a secured solution to use sort in dynamic fields 2026-08-15 17:54:12 +02:00
ai Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
api Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-13 17:48:25 +02:00
asset Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-14 15:54:52 +02:00
asterisk
barcode
blockedlog Debug v24 2026-08-13 20:14:53 +02:00
bom Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
bookcal Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
bookmarks Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
categories Qual: Fix 'SqlInjection' notices (#39213) 2026-07-19 17:32:14 +02:00
collab
comm FIX Agenda "per user" view does not fire printFieldListFrom hook (#39507) 2026-08-15 02:29:45 +02:00
commande Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-14 15:54:52 +02:00
compta Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-13 17:48:25 +02:00
conf
contact Fix old image not deleted 2026-08-07 18:27:23 +02:00
contrat Hide duplicate section that is already visible in banner 2026-08-14 14:30:50 +02:00
core Add dolSort to offer a secured solution to use sort in dynamic fields 2026-08-15 17:54:12 +02:00
cron Qual: Fix 'SqlInjection' notices (#39221) 2026-07-20 02:51:11 +02:00
custom
datapolicy Qual: Fix 'SqlInjection' notices (#39213) 2026-07-19 17:32:14 +02:00
dav Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386) 2026-08-04 22:23:57 +02:00
debugbar
delivery Qual: Fix 'SqlInjection' notices (#39219) 2026-07-20 02:50:44 +02:00
don Qual: Fix 'SqlInjection' notices (#39225) 2026-07-20 02:52:07 +02:00
ecm fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
emailcollector Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
eventorganization fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
expedition Automated merge from 21.0 to 22.0 by tool pullmerge.sh 2026-08-13 17:18:40 +02:00
expensereport Fix must exclude some properties in post/put of expensereport api - 2026-08-09 19:59:33 +02:00
exports Fix deletion must not use the glob by default. 2026-07-29 13:20:28 +02:00
fichinter FIX: CommonObject::updateExtraField() method should call the corresponding object update trigger (#39526) 2026-08-15 02:06:08 +02:00
fourn Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-14 15:54:52 +02:00
ftp
holiday Qual: Fix 'SqlInjection' notices (#39232) 2026-08-01 23:54:52 +02:00
hrm Fix deletion must not use the glob by default. 2026-07-29 13:20:28 +02:00
imports Redo #39379 2026-08-04 22:46:09 +02:00
includes
install Add dolSort to offer a secured solution to use sort in dynamic fields 2026-08-15 17:54:12 +02:00
intracommreport Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
knowledgemanagement fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
langs Trans 2026-08-15 19:18:41 +02:00
loan Qual: Fix 'SqlInjection' notices (#39225) 2026-07-20 02:52:07 +02:00
mailmanspip/class
margin Qual: Update SQL query variables for situation mode in margin reports (#39282) 2026-07-27 13:02:34 +02:00
modulebuilder Prepare more generic definition of MCP server 2026-08-13 03:20:02 +02:00
mrp Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-14 15:54:52 +02:00
multicurrency Qual: Fix phan notices (#39354) 2026-08-04 16:40:20 +02:00
opensurvey Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
partnership fix: Replace db->escape with db->sanitize in SQL query construction (#39357) 2026-08-04 18:40:04 +02:00
paypal FIX: PayPal API calls set CURLOPT_SSL_VERIFYHOST to a bool instead of 2 (#39155) 2026-07-16 02:23:26 +02:00
printing
product Fix escape js string - reported by Vulncheck 2026-08-14 15:43:43 +02:00
projet Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-13 17:48:25 +02:00
public Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
quickmemo FIX : Require write permission and check owner for unarchive memo (#39344) 2026-07-31 19:04:39 +02:00
reception Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
recruitment Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
resource Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
salaries Qual: Remove unnecessary quotes around integer values in SQL queries (#39290) 2026-07-27 12:59:14 +02:00
societe Fix prevent edit by external users - reported by VulnCheck 2026-08-16 06:31:33 +02:00
stripe
subtotals
supplier_invoice/admin
supplier_order/admin
supplier_proposal Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
takepos Qual: Fix 'SqlInjection' notices (#39232) 2026-08-01 23:54:52 +02:00
theme Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
ticket Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-06 00:35:00 +02:00
user Fix AISLE-2026-0340-0087 IDOR in user bank account edit flow - reported 2026-08-14 18:10:58 +02:00
variants Qual: Fix 'SqlInjection' notices (#39223) 2026-07-20 02:51:42 +02:00
webhook Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
webportal Qual: Fix 'SqlInjection' notices (#39232) 2026-08-01 23:54:52 +02:00
webservices Qual: Fix 'SqlInjection' notices (#39229) 2026-07-20 15:26:43 +02:00
website Fix option blocked by waf 2026-08-15 15:55:22 +02:00
workstation Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286) 2026-07-27 13:00:33 +02:00
zapier
document.php Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0 2026-08-13 17:16:49 +02:00
favicon.ico
filefunc.inc.php
index.php
main.inc.php Clean code 2026-08-07 19:00:27 +02:00
master.inc.php
robots.txt
security.txt
version.inc.php Prepare 24.0 release 2026-08-12 22:04:04 +02:00
viewimage.php Fix file access with hasp parameter - reported by tremor hunter 2026-08-12 22:16:43 +02:00
waf.inc.php Fix: more complete blacklist in waf - reported by Paweł Bednarz 2026-08-09 02:01:05 +02:00