CVE-2026-31018: Dolibarr Erp/crm
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.
Affected products
- Dolibarr Dolibarr Erp/crm: up to and including 22.0.4
Published 2026-04-21. Last modified 2026-07-05.