Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-32px-ccfx-cxq3 | Krayin CRM allows a remote attacker to execute arbitrary code via compose email function |
Sat, 02 May 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Remote Code Execution via Compose Email in Krayin CRM 2.1.5 |
Thu, 30 Apr 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Krayin
Krayin laravel-crm |
|
| Vendors & Products |
Krayin
Krayin laravel-crm |
Thu, 30 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-94 | |
| Metrics |
cvssV3_1
|
Thu, 30 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in Krayin CRM v.2.1.5 and fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-30T17:14:28.330Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36340
Updated: 2026-04-30T17:12:01.890Z
Status : Deferred
Published: 2026-04-30T16:16:42.160
Modified: 2026-04-30T18:16:28.147
Link: CVE-2026-36340
No data.
OpenCVE Enrichment
Updated: 2026-05-02T12:00:14Z
Github GHSA