CVE-2026-31018

In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:*

History

23 Apr 2026, 16:15

Type Values Removed Values Added
CPE cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:*
References () http://dolibarr.com - () http://dolibarr.com - Product
References () https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31018/README.md - () https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31018/README.md - Third Party Advisory
First Time Dolibarr
Dolibarr dolibarr Erp\/crm

21 Apr 2026, 16:16

Type Values Removed Values Added
CWE CWE-284
CWE-94
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.8

21 Apr 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-21 15:16

Updated : 2026-04-23 16:15


NVD link : CVE-2026-31018

Mitre link : CVE-2026-31018

CVE.ORG link : CVE-2026-31018


JSON object : View

Products Affected

dolibarr

  • dolibarr_erp\/crm
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')

CWE-284

Improper Access Control