← Vulnerability feed

Vulnerability record · CVE-2018-9019 · published 22 May 2018

CVE-2018-9019: Dolibarr sql injection vulnerability

Dolibarr · Dolibarr

SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.

9.8 CVSS 3.1 Critical EPSS 4.0% · top 9.9% CWE-89 · SQL injection
9.8CVSS 3.1 base score, v2 7.5
4.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

SQL Injection vulnerability in Dolibarr before version 7.0.2 allows remote attackers to execute arbitrary SQL commands via the sortfield parameter to /accountancy/admin/accountmodel.php, /accountancy/admin/categories_list.php, /accountancy/admin/journals_list.php, /admin/dict.php, /admin/mails_templates.php, or /admin/website.php.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2018-9019 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2026-47056Oracle data integrator missing authentication for critical function vulnerabilityVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). Supported versions that are affected are 1…EPSS 0.51%9.8CVE-2026-60999Oracle data integrator improper access control vulnerabilityVulnerability in the Oracle Data Integrator product of Oracle Fusion Middleware (component: Rest Service). The supported version that is affected is …EPSS 0.51%9.8CVE-2020-10683Dom4j project dom4j xml external entity (xxe) vulnerabilitydom4j before 2.0.3 and 2.1.x before 2.1.3 allows external DTDs and External Entities by default, which might enable XXE attacks. However, there is po…EPSS 7.3%9.8CVE-2019-19212Dolibarr cross-site scripting vulnerabilityDolibarr ERP/CRM 3.0 through 10.0.3 allows XSS via the qty parameter to product/fournisseurs.php (product price screen).EPSS 3.9%9.8CVE-2019-17195Connect2id nimbus jose\+jwt vulnerabilityConnect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potenti…EPSS 11%9.8CVE-2018-16809Dolibarr sql injection vulnerabilityAn issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer paramete…EPSS 2.2%9.8CVE-2018-1000613Bouncycastle bc-java vulnerabilityLegion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externall…EPSS 4.8%9.8CVE-2018-8013Apache batik deserialization of untrusted data vulnerabilityIn Apache Batik 1.x before 1.10, when deserializing subclass of `AbstractDocument`, the class takes a string from the inputStream as the class name w…EPSS 19%

Source: NIST National Vulnerability Database (record CVE-2018-9019), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.