In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.
References
| Link | Resource |
|---|---|
| http://dolibarr.com | Product |
| https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31018/README.md | Third Party Advisory |
Configurations
History
23 Apr 2026, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | |
| References | () http://dolibarr.com - Product | |
| References | () https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31018/README.md - Third Party Advisory | |
| First Time |
Dolibarr
Dolibarr dolibarr Erp\/crm |
21 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-284 CWE-94 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
21 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 15:16
Updated : 2026-04-23 16:15
NVD link : CVE-2026-31018
Mitre link : CVE-2026-31018
CVE.ORG link : CVE-2026-31018
JSON object : View
Products Affected
dolibarr
- dolibarr_erp\/crm
