CVE-2026-5370
published 2026-04-02CVE-2026-5370: A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file…
PriorityP415low3.5CVSS 3.1
AVNACLPRLUIRSUCNILAN
EPSS
0.20%
10.6th percentile
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | 0 – 2.2.0 | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
nvdv4.02.0LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
osv·2026-04-02
CVE-2026-5370 [LOW] Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch.
GHSA
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
ghsa·2026-04-02
CVE-2026-5370 [LOW] CWE-79 Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch.
No detection rules found.
No public exploits indexed.
https://github.com/krayin/laravel-crm/https://github.com/krayin/laravel-crm/commit/73ed28d466bf14787fdb86a120c656a4af270153https://github.com/krayin/laravel-crm/issues/2419https://github.com/krayin/laravel-crm/pull/2466https://vuldb.com/submit/781666https://vuldb.com/vuln/354756https://vuldb.com/vuln/354756/cti
2026-04-02
Published