CVE-2026-31018: Dolibarr Erp/crm

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to inject PHP code through unprotected inputs during website page creation.

Affected products

  • Dolibarr Dolibarr Erp/crm: up to and including 22.0.4

Published 2026-04-21. Last modified 2026-07-05.