CVE-2026-97897
published 2026-09-25CVE-2026-97897: A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component…
PriorityP418low3.5CVSS 3.1
AVNACLPRLUIRSUCNILAN
EPSS
0.24%
13.5th percentile
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. You should upgrade the affected component.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
| krayin | laravel-crm | — | — |
CVSS provenance
nvdv3.13.5LOWCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
nvdv4.05.1MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.mdhttps://github.com/krayin/laravel-crm/https://github.com/krayin/laravel-crm/commit/734aa10ae6c2ffa4c96c8869a89aa66940e4d345https://github.com/krayin/laravel-crm/pull/2639https://github.com/krayin/laravel-crm/releases/tag/v2.2.6https://vuldb.com/cve/CVE-2026-97897https://vuldb.com/submit/915413https://vuldb.com/vuln/409909https://vuldb.com/vuln/409909/ctihttps://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.md
2026-09-25
Published