Technology · Dolibarr
Dolibarr ERP CRM vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 15 vulnerabilities in Dolibarr ERP CRM: 0 in the last 7 days and 2 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-81031, was published on 26 August 2026.
- Last 7 days
- 0
- Last 90 days
- 2
- Critical, all time
- 1
- Exploited in the wild
- 0
About Dolibarr ERP CRM
Dolibarr ERP CRM is an open-source software suite for small and medium companies, foundations, and freelancers to manage business activities like contacts, invoices, orders, and inventory.
Latest Dolibarr ERP CRM vulnerabilities
- CVE-2026-81031: IDURAR ERP CRM privilege escalation via password resethighCVSS 7.2EPSS 0.6%
- CVE-2026-72600: Idurar ERP CRM broken access control in invoice downloadhighCVSS 7.5EPSS 0.6%
- CVE-2026-11619: Dolibarr ERP CRM improper authorization in Legacy FilemanagermediumCVSS 6.3
- CVE-2026-10215: Dolibarr ERP CRM improper authorization in Leave Request REST APImediumCVSS 4.3EPSS 0.3%
- CVE-2026-10154: Dolibarr ERP CRM authorization bypass in messaging.phpmediumCVSS 4.3
- CVE-2026-37713: Dolibarr ERP/CRM PHP code execution in CommonObject classinfoCVSS 8.1
- CVE-2026-37712: Dolibarr ERP/CRM remote code execution in cron schedulerinfoCVSS 9.1
- CVE-2026-37711: Dolibarr ERP/CRM remote code execution in actions_addupdatedelete.inc.phpinfoCVSS 9.1
- CVE-2018-25357: Dolibarr ERP CRM PHP code injection in install/step1.phpcriticalCVSS 9.8EPSS 1.7%
- CVE-2025-67486: Dolibarr ERP/CRM remote code execution in user extrafieldshighCVSS 7.2
- CVE-2026-7688: Dolibarr ERP CRM SQL injection in Shipments API EndpointmediumCVSS 5
- CVE-2026-31019: Dolibarr ERP & CRM RCE via blacklist bypass in Website modulehighCVSS 8.8EPSS 0.6%
- CVE-2026-31018: Dolibarr ERP & CRM PHP code injection in Website modulehighCVSS 8.8EPSS 0.3%
- CVE-2026-22666: Dolibarr ERP/CRM remote code execution in dol_eval_standardhighCVSS 7.2EPSS 15.5%
- CVE-2025-56588: Dolibarr ERP & CRM remote code execution in User module computed fieldhighCVSS 8.8EPSS 0.5%
Most severe Dolibarr ERP CRM vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2018-25357: Dolibarr ERP CRM PHP code injection in install/step1.phpcriticalCVSS 9.8EPSS 1.7%
- CVE-2026-31019: Dolibarr ERP & CRM RCE via blacklist bypass in Website modulehighCVSS 8.8EPSS 0.6%
- CVE-2025-56588: Dolibarr ERP & CRM remote code execution in User module computed fieldhighCVSS 8.8EPSS 0.5%
- CVE-2026-31018: Dolibarr ERP & CRM PHP code injection in Website modulehighCVSS 8.8EPSS 0.3%
- CVE-2026-72600: Idurar ERP CRM broken access control in invoice downloadhighCVSS 7.5EPSS 0.6%
- CVE-2026-22666: Dolibarr ERP/CRM remote code execution in dol_eval_standardhighCVSS 7.2EPSS 15.5%
- CVE-2026-81031: IDURAR ERP CRM privilege escalation via password resethighCVSS 7.2EPSS 0.6%
- CVE-2025-67486: Dolibarr ERP/CRM remote code execution in user extrafieldshighCVSS 7.2
- CVE-2026-11619: Dolibarr ERP CRM improper authorization in Legacy FilemanagermediumCVSS 6.3
- CVE-2026-7688: Dolibarr ERP CRM SQL injection in Shipments API EndpointmediumCVSS 5
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 1 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/erp-crm.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Dolibarr ERP CRM vulnerabilities", https://junglewise.ai/threats/technologies/erp-crm, 26 September 2026.