GHSA-j2g9-rprv-hrhc · Severity: high · Ecosystem: composer — Dolibarr user with permission to edit PHP content can bypass filtering to restrict dangerous PHP functions
In the Website module of Dolibarr ERP & CRM 22.0.4 and below, the application uses blacklist-based filtering to restrict dangerous PHP functions related to system command execution. An authenticated user with permission to edit PHP content can bypass this filtering, resulting in full remote code execution with the ability to execute arbitrary operating system commands on the server.
Conclusion & alert: CVE-2026-31019 is rated Moderate Risk (47.5/100): CVSS High severity, with low exploitation likelihood (EPSS 0.15%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-22 | — | 0.15% | — |
Full EPSS history (1 record total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
GHSA-j2g9-rprv-hrhc · Severity: high · Ecosystem: composer — Dolibarr user with permission to edit PHP content can bypass filtering to restrict dangerous PHP functions
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2026-31019 medium priority: Ubuntu including 1 source packages (dolibarr), 6 status rows across 6 suites (jammy, noble, questing, resolute, upstream, xenial): DNE 4, needs-triage 2. | https://ubuntu.com/security/CVE-2026-31019 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| dolibarr | dolibarr_erp\/crm | <= 22.0.4 | cpe:2.3:a:dolibarr:dolibarr_erp\/crm:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| http://dolibarr.com | Product |
| https://github.com/PhDg1410/CVE/blob/main/CVE-2026-31019/README.md | Third Party Advisory |