Dolibarr Vulnerabilities and Affected Products
Vulnerabilities associated with Dolibarr ERP CRM.
Products
Clear product- dolibarr18 vulnerabilities
- dolibarr/dolibarr11 vulnerabilities
- ERP CRM5 vulnerabilities
- dolibarr_erp\/crm4 vulnerabilities
- Dolibarr ERP CRM3 vulnerabilities
- Dolibarr ERP/CRM3 vulnerabilities
- ERP CMS2 vulnerabilities
- CRM1 vulnerability
- Dolibarr ERP-CRM1 vulnerability
- ERP1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2018-25357CRITICAL | Dolibarr ERP CRM 7.0.3 Remote Code Execution via install/step1.phpDolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers can send a POST request to install/step1.php with malicious PHP code in the db_name parameter, then execute commands via the check.php endpoint using the cmd GET parameter. CWE-94May 23, 2026 | CVSS9.3v4.0 | EPSS1.7% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4198MEDIUM | Dolibarr ERP CRM (<= 17.0.3) Improper Access ControlImproper Access Control in Dolibarr ERP CRM <= v17.0.3 allows an unauthorized authenticated user to read a database table containing customer data CWE-862Nov 1, 2023 | CVSS6.5v3.1 | EPSS0.555% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-4197HIGH | Dolibarr ERP CRM (<= 18.0.1) Improper Input Sanitization Authenticated RCEImproper input validation in Dolibarr ERP CRM <= v18.0.1 fails to strip certain PHP code from user-supplied input when creating a Website, allowing an attacker to inject and evaluate arbitrary PHP code. | CVSS7.5v3.1 | EPSS32.8% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |