Krayin Laravel-Crm vulnerabilities
24 known vulnerabilities affecting krayin/laravel-crm.
Total CVEs
24
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM10LOW4
Vulnerabilities
Page 1 of 2
CVE-2026-41452P1CRITICALCVSS 9.8PoC≤ 2.2.0v2.2.42026-08-03
CVE-2026-41452 [CRITICAL] CWE-306 CVE-2026-41452: Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that al
Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to bypass the CanInstall middleware redirect check. Attackers can supply arb
nvd
CVE-2026-100885P2HIGHCVSS 7.3PoCv2.2.0v2.2.1+3 more2026-09-27
CVE-2026-100885 [HIGH] CWE-285 CVE-2026-100885: A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be u
nvd
CVE-2026-41453P2HIGHCVSS 8.8fixed in 2.2.42026-08-03
CVE-2026-41453 [HIGH] CWE-89 CVE-2026-41453: Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allo
Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw() call in LeadDataGrid.php. Attackers
nvd
CVE-2026-38529P3HIGH≥ 0, ≤ 2.2.02026-04-14
CVE-2026-38529 [HIGH] CWE-269 Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.
ghsa
CVE-2026-61460P3HIGHCVSS 8.8≤ 2.2.32026-07-10
CVE-2026-61460 [HIGH] CWE-639 CVE-2026-61460: Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadControlle
Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users. Attackers can modify CRM records and reassign ownership by exploiting missing r
nvd
CVE-2026-90944P3HIGHCVSS 8.2≤ 2.2.62026-09-14
CVE-2026-90944 [HIGH] CWE-306 CVE-2026-90944: Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication,
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body, including replies to existing conver
nvd
CVE-2026-36340P3HIGH≥ 2.1.5, < 2.1.62026-04-30
CVE-2026-36340 [HIGH] CWE-94 Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
An issue in Krayin CRM v.2.1.5, which was fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function.
ghsa
CVE-2026-38532P3HIGH≥ 0, ≤ 2.2.02026-04-14
CVE-2026-38532 [HIGH] CWE-639 Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplyin
ghsa
CVE-2026-38530P3HIGH≥ 0, ≤ 2.2.02026-04-14
CVE-2026-38530 [HIGH] CWE-639 Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a cr
ghsa
CVE-2026-38527P3HIGH≥ 0, ≤ 2.2.02026-04-14
CVE-2026-38527 [HIGH] CWE-918 Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.
ghsa
CVE-2026-100883P3MEDIUMCVSS 6.3v2.2.0v2.2.1+4 more2026-09-27
CVE-2026-100883 [MEDIUM] CWE-266 CVE-2026-100883: A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function
A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. Executing a manipulation can lead to improper access controls. The attack can be launched remotely. The exploit has been published and may be used. Upgrading to version 2.2.6 is sufficient to fi
nvd
CVE-2026-97895P3MEDIUMCVSS 6.3v2.2.0v2.2.1+4 more2026-09-25
CVE-2026-97895 [MEDIUM] CWE-266 CVE-2026-97895: A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of th
A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument role_id can lead to improper privilege management. The attack can be executed remotely. The exploi
nvd
CVE-2026-48540P4MEDIUMCVSS 5.4≤ 2.2.62026-09-24
CVE-2026-48540 [MEDIUM] CWE-79 CVE-2026-48540: Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attackers can craft a lead title containing double-brace template syntax that reaches the Vue template c
nvd
CVE-2026-48541P4MEDIUMCVSS 5.4≤ 2.2.62026-09-24
CVE-2026-48541 [MEDIUM] CWE-79 CVE-2026-48541: Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person name field. Attackers can craft a person name containing double-brace template syntax that reaches the Vue template
nvd
CVE-2026-48542P4MEDIUMCVSS 5.4≤ 2.2.62026-09-24
CVE-2026-48542 [MEDIUM] CWE-79 CVE-2026-48542: Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the product name field. Attackers can craft a product name containing double-brace template syntax that reaches the Vue templa
nvd
CVE-2026-48543P4MEDIUMCVSS 5.4≤ 2.2.62026-09-24
CVE-2026-48543 [MEDIUM] CWE-79 CVE-2026-48543: Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web form description field. Attackers can craft a web form description containing double-brace template syntax that reache
nvd
CVE-2026-100884P4MEDIUMCVSS 4.3v2.2.0v2.2.1+4 more2026-09-27
CVE-2026-100884 [MEDIUM] CWE-99 CVE-2026-100884: A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the functi
A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file packages/Webkul/Admin/src/Config/acl.php of the component attachment-download Endpoint. The manipulation of the argument ID leads to improper control of resource identifiers. The attack may be initiated remotely. The
nvd
CVE-2026-36341P4MEDIUM≥ 2.1.5, < 2.1.62026-05-07
CVE-2026-36341 [MEDIUM] CWE-79 Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
ghsa
CVE-2021-41924P4MEDIUM≥ 0, < 1.2.22022-06-22
CVE-2021-41924 [MEDIUM] CWE-79 Cross-site Scripting in krayin/laravel-crm
Cross-site Scripting in krayin/laravel-crm
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS).
ghsaosv
CVE-2026-97896P4LOWCVSS 3.5v2.2.0v2.2.1+4 more2026-09-25
CVE-2026-97896 [LOW] CWE-79 CVE-2026-97896: A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the fun
A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit
nvd
1 / 2Next →