CVE-2026-100882
published 2026-09-27CVE-2026-100882: A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file…
PriorityP413low2.4CVSS 3.1
AVNACLPRHUIRSUCNILAN
EPSS
0.26%
15.9th percentile
A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
CVSS provenance
nvdv3.12.4LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
nvdv4.01.9LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.03.3LOWAV:N/AC:L/Au:M/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Krayin laravel-crm up to 2.2.5 Admin Settings Endpoint index.blade.php general.settings.footer.label cross site scripting (Issue 2622 / EUVD-2026-88045)
vuldb·2026-09-28·CVSS 2.4
CVE-2026-100882 [LOW] Krayin laravel-crm up to 2.2.5 Admin Settings Endpoint index.blade.php general.settings.footer.label cross site scripting (Issue 2622 / EUVD-2026-88045)
A vulnerability identified as problematic has been detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting.
This vulnerability is identified as CVE-2026-100882. The attack can be initiated remotely. Additionally, an exploit exists.
You should upgrade the affected component.
GHSA
A vulnerability was detected in Krayin laravel-crm up to 2.2.5.
ghsa_unreviewed·2026-09-28
CVE-2026-100882 [LOW] CWE-79 A vulnerability was detected in Krayin laravel-crm up to 2.2.5.
A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be used. Upgrading to version 2.2.6 is recommended to address this issue. The patch is named 6dbcf75b30dbd169ee81b7e9e00368099124efeb. You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/carlosalbertotuma/advisory/blob/main/advisory-04-stored-xss-via-footer.mdhttps://github.com/krayin/laravel-crm/https://github.com/krayin/laravel-crm/commit/6dbcf75b30dbd169ee81b7e9e00368099124efebhttps://github.com/krayin/laravel-crm/issues/2622https://github.com/krayin/laravel-crm/pull/2625https://github.com/krayin/laravel-crm/releases/tag/v2.2.6https://vuldb.com/cve/CVE-2026-100882https://vuldb.com/submit/916088https://vuldb.com/vuln/410812https://vuldb.com/vuln/410812/cti
2026-09-27
Published