Krayin Laravel-Crm vulnerabilities
24 known vulnerabilities affecting krayin/laravel-crm.
Total CVEs
24
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH9MEDIUM10LOW4
Vulnerabilities
Page 2 of 2
CVE-2026-97897P4LOWCVSS 3.5v2.2.0v2.2.1+4 more2026-09-25
CVE-2026-97897 [LOW] CWE-79 CVE-2026-97897: A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unkno
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identifi
nvd
CVE-2026-5370P4LOWCVSS 3.5v2.0v2.1+1 more2026-04-02
CVE-2026-5370 [LOW] CWE-79 CVE-2026-5370: A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and mi
ghsanvdosv
CVE-2024-45932P4MEDIUM≥ 0, ≤ 1.3.02024-10-07
CVE-2024-45932 [MEDIUM] CWE-79 Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in `/admin/contacts/organizations/edit/2`.
ghsaosv
CVE-2026-100882P4LOWCVSS 2.4v2.2.0v2.2.1+4 more2026-09-27
CVE-2026-100882 [LOW] CWE-79 CVE-2026-100882: A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of t
A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be ini
nvd
← Previous2 / 2