Showing 3 vulnerabilities on this page for Dolibarr ERP CRM

Signals CISA KEV Ransomware Nuclei
Dolibarr vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.php

Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter.

CWE-94May 23, 2026
CVSS9.3v4.0EPSS1.7%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Dolibarr ERP CRM (<= 17.0.3) Improper Access Control

Improper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data

CWE-862Nov 1, 2023
CVSS6.5v3.1EPSS0.555%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Dolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCE

Improper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code.

CWE-20CWE-74Nov 1, 2023
CVSS7.5v3.1EPSS32.8%PoCs1SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX