In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code execution with the ability to execute arbitrary operating system commands on the server.
References
| Link | Resource |
|---|---|
| https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31019/README.md | Third Party Advisory |
Configurations
History
05 Jul 2026, 02:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
23 Apr 2026, 16:10
| Type | Values Removed | Values Added |
|---|---|---|
| References | () http://dolibarr.com - Product | |
| References | () https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31019/README.md - Third Party Advisory | |
| CPE | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* | |
| First Time |
Dolibarr
Dolibarr dolibarr Erp\/crm |
21 Apr 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| CWE | CWE-78 |
21 Apr 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-21 15:16
Updated : 2026-07-05 02:17
NVD link : CVE-2026-31019
Mitre link : CVE-2026-31019
CVE.ORG link : CVE-2026-31019
JSON object : View
Products Affected
dolibarr
- dolibarr_erp\/crm
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
