| .. |
|
accountancy
|
Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-13 17:48:25 +02:00 |
|
adherents
|
Fix(ci): security access check (#39530)
|
2026-08-15 01:58:01 +02:00 |
|
admin
|
Add dolSort to offer a secured solution to use sort in dynamic fields
|
2026-08-15 17:54:12 +02:00 |
|
ai
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
api
|
Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-13 17:48:25 +02:00 |
|
asset
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-14 15:54:52 +02:00 |
|
asterisk
|
|
|
|
barcode
|
|
|
|
blockedlog
|
Debug v24
|
2026-08-13 20:14:53 +02:00 |
|
bom
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
bookcal
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
bookmarks
|
Qual: Fix 'SqlInjection' notices (#39223)
|
2026-07-20 02:51:42 +02:00 |
|
categories
|
Qual: Fix 'SqlInjection' notices (#39213)
|
2026-07-19 17:32:14 +02:00 |
|
collab
|
|
|
|
comm
|
FIX Agenda "per user" view does not fire printFieldListFrom hook (#39507)
|
2026-08-15 02:29:45 +02:00 |
|
commande
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-14 15:54:52 +02:00 |
|
compta
|
Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-13 17:48:25 +02:00 |
|
conf
|
|
|
|
contact
|
Fix old image not deleted
|
2026-08-07 18:27:23 +02:00 |
|
contrat
|
Hide duplicate section that is already visible in banner
|
2026-08-14 14:30:50 +02:00 |
|
core
|
Add dolSort to offer a secured solution to use sort in dynamic fields
|
2026-08-15 17:54:12 +02:00 |
|
cron
|
Qual: Fix 'SqlInjection' notices (#39221)
|
2026-07-20 02:51:11 +02:00 |
|
custom
|
|
|
|
datapolicy
|
Qual: Fix 'SqlInjection' notices (#39213)
|
2026-07-19 17:32:14 +02:00 |
|
dav
|
Revert "/imports/index.php wrongly shows access refused (#39379)" (#39386)
|
2026-08-04 22:23:57 +02:00 |
|
debugbar
|
|
|
|
delivery
|
Qual: Fix 'SqlInjection' notices (#39219)
|
2026-07-20 02:50:44 +02:00 |
|
don
|
Qual: Fix 'SqlInjection' notices (#39225)
|
2026-07-20 02:52:07 +02:00 |
|
ecm
|
fix: Replace db->escape with db->sanitize in SQL query construction (#39357)
|
2026-08-04 18:40:04 +02:00 |
|
emailcollector
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-06 00:35:00 +02:00 |
|
eventorganization
|
fix: Replace db->escape with db->sanitize in SQL query construction (#39357)
|
2026-08-04 18:40:04 +02:00 |
|
expedition
|
Automated merge from 21.0 to 22.0 by tool pullmerge.sh
|
2026-08-13 17:18:40 +02:00 |
|
expensereport
|
Fix must exclude some properties in post/put of expensereport api -
|
2026-08-09 19:59:33 +02:00 |
|
exports
|
Fix deletion must not use the glob by default.
|
2026-07-29 13:20:28 +02:00 |
|
fichinter
|
FIX: CommonObject::updateExtraField() method should call the corresponding object update trigger (#39526)
|
2026-08-15 02:06:08 +02:00 |
|
fourn
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-14 15:54:52 +02:00 |
|
ftp
|
|
|
|
holiday
|
Qual: Fix 'SqlInjection' notices (#39232)
|
2026-08-01 23:54:52 +02:00 |
|
hrm
|
Fix deletion must not use the glob by default.
|
2026-07-29 13:20:28 +02:00 |
|
imports
|
Redo #39379
|
2026-08-04 22:46:09 +02:00 |
|
includes
|
|
|
|
install
|
Add dolSort to offer a secured solution to use sort in dynamic fields
|
2026-08-15 17:54:12 +02:00 |
|
intracommreport
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
knowledgemanagement
|
fix: Replace db->escape with db->sanitize in SQL query construction (#39357)
|
2026-08-04 18:40:04 +02:00 |
|
langs
|
Trans
|
2026-08-15 19:18:41 +02:00 |
|
loan
|
Qual: Fix 'SqlInjection' notices (#39225)
|
2026-07-20 02:52:07 +02:00 |
|
mailmanspip/class
|
|
|
|
margin
|
Qual: Update SQL query variables for situation mode in margin reports (#39282)
|
2026-07-27 13:02:34 +02:00 |
|
modulebuilder
|
Prepare more generic definition of MCP server
|
2026-08-13 03:20:02 +02:00 |
|
mrp
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-14 15:54:52 +02:00 |
|
multicurrency
|
Qual: Fix phan notices (#39354)
|
2026-08-04 16:40:20 +02:00 |
|
opensurvey
|
Qual: Fix 'SqlInjection' notices (#39223)
|
2026-07-20 02:51:42 +02:00 |
|
partnership
|
fix: Replace db->escape with db->sanitize in SQL query construction (#39357)
|
2026-08-04 18:40:04 +02:00 |
|
paypal
|
FIX: PayPal API calls set CURLOPT_SSL_VERIFYHOST to a bool instead of 2 (#39155)
|
2026-07-16 02:23:26 +02:00 |
|
printing
|
|
|
|
product
|
Fix escape js string - reported by Vulncheck
|
2026-08-14 15:43:43 +02:00 |
|
projet
|
Merge branch '24.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-13 17:48:25 +02:00 |
|
public
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-06 00:35:00 +02:00 |
|
quickmemo
|
FIX : Require write permission and check owner for unarchive memo (#39344)
|
2026-07-31 19:04:39 +02:00 |
|
reception
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-06 00:35:00 +02:00 |
|
recruitment
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
resource
|
Qual: Fix 'SqlInjection' notices (#39223)
|
2026-07-20 02:51:42 +02:00 |
|
salaries
|
Qual: Remove unnecessary quotes around integer values in SQL queries (#39290)
|
2026-07-27 12:59:14 +02:00 |
|
societe
|
Fix prevent edit by external users - reported by VulnCheck
|
2026-08-16 06:31:33 +02:00 |
|
stripe
|
|
|
|
subtotals
|
|
|
|
supplier_invoice/admin
|
|
|
|
supplier_order/admin
|
|
|
|
supplier_proposal
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-06 00:35:00 +02:00 |
|
takepos
|
Qual: Fix 'SqlInjection' notices (#39232)
|
2026-08-01 23:54:52 +02:00 |
|
theme
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-06 00:35:00 +02:00 |
|
ticket
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-06 00:35:00 +02:00 |
|
user
|
Fix AISLE-2026-0340-0087 IDOR in user bank account edit flow - reported
|
2026-08-14 18:10:58 +02:00 |
|
variants
|
Qual: Fix 'SqlInjection' notices (#39223)
|
2026-07-20 02:51:42 +02:00 |
|
webhook
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
webportal
|
Qual: Fix 'SqlInjection' notices (#39232)
|
2026-08-01 23:54:52 +02:00 |
|
webservices
|
Qual: Fix 'SqlInjection' notices (#39229)
|
2026-07-20 15:26:43 +02:00 |
|
website
|
Fix option blocked by waf
|
2026-08-15 15:55:22 +02:00 |
|
workstation
|
Qual/Sec: Use db->sanitize instead of db->escape when not quoted, fix some quoting (#39286)
|
2026-07-27 13:00:33 +02:00 |
|
zapier
|
|
|
|
document.php
|
Merge branch '23.0' of git@github.com:Dolibarr/dolibarr.git into 24.0
|
2026-08-13 17:16:49 +02:00 |
|
favicon.ico
|
|
|
|
filefunc.inc.php
|
|
|
|
index.php
|
|
|
|
main.inc.php
|
Clean code
|
2026-08-07 19:00:27 +02:00 |
|
master.inc.php
|
|
|
|
robots.txt
|
|
|
|
security.txt
|
|
|
|
version.inc.php
|
Prepare 24.0 release
|
2026-08-12 22:04:04 +02:00 |
|
viewimage.php
|
Fix file access with hasp parameter - reported by tremor hunter
|
2026-08-12 22:16:43 +02:00 |
|
waf.inc.php
|
Fix: more complete blacklist in waf - reported by Paweł Bednarz
|
2026-08-09 02:01:05 +02:00 |