CVE-2026-36341
published 2026-05-07CVE-2026-36341: Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during…
PriorityP427medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
EPSS
0.30%
20.5th percentile
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| krayin | laravel-crm | >= 2.1.5 < 2.1.6 | 2.1.6 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
ghsa·2026-05-07
CVE-2026-36341 [MEDIUM] CWE-79 Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
GHSA
GHSA-j822-46r5-h4qx: Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2
ghsa_unreviewed·2026-05-07
CVE-2026-36341 [MEDIUM] CWE-79 GHSA-j822-46r5-h4qx: Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
VulDB
Krayin CRM 2.1.5 /admin/activities/create Comment cross site scripting
vuldb·2026-05-07·CVSS 5.4
CVE-2026-36341 [MEDIUM] Krayin CRM 2.1.5 /admin/activities/create Comment cross site scripting
A vulnerability described as problematic has been identified in Krayin CRM 2.1.5. This impacts an unknown function of the file /admin/activities/create. Such manipulation of the argument Comment leads to cross site scripting.
This vulnerability is listed as CVE-2026-36341. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is recommended.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cyber.spool.co.jp/vulnerabilities/cve-2026-36341/https://drive.google.com/file/d/1Y_WjD4Tiq_z7zQUlddFCFMDoyyN300r9/viewhttps://github.com/cybercrewinc/CVE-2026-36341https://github.com/krayin/laravel-crm/pull/2401https://github.com/krayin/laravel-crm/releases/tag/v2.1.6https://cyber.spool.co.jp/vulnerabilities/cve-2026-36341/
2026-05-07
Published