Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-j822-46r5-h4qx | Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint |
Thu, 07 May 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in Webkul Krayin CRM 2.1.5 Comment Field |
Thu, 07 May 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Cross‑Site Scripting in Webkul Krayin CRM 2.1.5 Comment Field | |
| First Time appeared |
Krayin
Krayin laravel-crm |
|
| Vendors & Products |
Krayin
Krayin laravel-crm |
Thu, 07 May 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Thu, 07 May 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-05-07T16:14:52.978Z
Reserved: 2026-04-06T00:00:00.000Z
Link: CVE-2026-36341
Updated: 2026-05-07T16:14:48.288Z
Status : Deferred
Published: 2026-05-07T16:16:18.900
Modified: 2026-05-07T18:45:48.327
Link: CVE-2026-36341
No data.
OpenCVE Enrichment
Updated: 2026-05-07T19:30:27Z
Github GHSA