CVE-2025-67486High· 7.2▾ TwilightDolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionalit…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.6 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerability in the user extrafields functionality. User-controlled input from the "computed value" field is passed to PHP's eval() function without adequate sanitization, allowing authenticated administrators to execute arbitrary PHP code on the server. As of time of publication, no patched versions are available.
dolibarr_erp/crm <= 22.0.2Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2025-14884High· 7.2A vulnerability was detected in D-Link DIR-605 202WWB03
CVE-2021-47779Medium· 5.4Dolibarr ERP-CRM 14.0.2 - Stored Cross-Site Scripting (XSS) / Privilege Escalation
CVE-2026-77923Medium· 4.3Dolibarr 21.0.0 < 24.0.0 Authorization Bypass via clonetasks Mass Action
CVE-2026-81729Medium· 6.5Dolibarr before 23.0.4 Incorrect Authorization on REST API Document Deletion
CVE-2026-81730High· 8.2Dolibarr 9.0.0 through 23.0.4 Path Traversal via EmailCollector Attachment Filename
CVE-2026-81728High· 8.1Dolibarr before 24.0.0 SQL Injection via the CSV and XLSX Import Update Keys