krayin/laravel-crm
Krayin CRM is Free & Open Source CRM Built with Laravel for Customer, Lead, and Sales Management.
Activity
- Latest release
- 5d ago
- Total releases
- 34
- Cadence
- ~21 days
- Last 12 months
- 8
Reach
- Stars
- 23.9k
Details
- License
- MIT
- First release
- Jul 21, 2021
| Version | Released | |
|---|---|---|
v2.2.6
patch
|
v2.2.6
patch
Dependencies (18)
+ 10 more
Changelog
Compare changes
|
|
v2.2.5
patch
|
v2.2.5
patch
Dependencies (17)
+ 9 more
Changelog
Compare changes
|
|
v2.2.4
patch
|
v2.2.4
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
v2.2.3
patch
| ||
v2.2.2
patch
| ||
v2.2.1
patch
| ||
v2.2.0
minor
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.1.6
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev |
v2.1.6
patch
Dependencies (16)
+ 8 more
Changelog
Compare changes
|
|
v2.1.5
patch
7 CVEs
CVE-2026-36341
GHSA-j822-46r5-h4qx
May 07, 2026
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint Affected versions
2.1.5
v2.1.5
Fixed in
2.1.6
References
Updated May 12, 2026 · Source: OSV.dev
CVE-2026-36340
GHSA-32px-ccfx-cxq3
Apr 30, 2026
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
An issue in Krayin CRM v.2.1.5, which was fixed in v.2.1.6 allows a remote attacker to execute arbitrary code via the compose email function. Affected versions
2.1.5
v2.1.5
Fixed in
2.1.6
References Updated May 07, 2026 · Source: OSV.dev
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.1.4
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.1.3
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.1.2
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.1.1
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.1.0
minor
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev |
v2.1.0
minor
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
v2.0.6
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev |
v2.0.6
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v2.0.5
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.0.4
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev |
v2.0.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.3.1
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev |
v1.3.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
v2.0.2
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.0.1
patch
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.0.0
major
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev | ||
v2.0.0-BETA-1
pre
5 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev |
v2.0.0-BETA-1
pre
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v1.3.0
minor
6 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev | ||
v1.2.4
patch
6 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev |
v1.2.4
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.2.3
patch
6 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev |
v1.2.3
patch
Dependencies (15)
+ 7 more
Changelog
Compare changes
|
|
v1.2.2
patch
6 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev |
v1.2.2
patch
Dependencies (13)
+ 5 more
Changelog
Compare changes
|
|
v1.2.1
patch
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.2.1
patch
Dependencies (12)
+ 4 more
Changelog
Compare changes
|
|
v1.2.0
minor
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.1.3
patch
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.1.3
patch
Dependencies (11)
+ 3 more
Changelog
Compare changes
|
|
v1.1.2
patch
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.1.1
patch
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.1.0
minor
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev | ||
v1.0.1
patch
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev |
v1.0.1
patch
Dependencies (10)
+ 2 more
Changelog
Compare changes
|
|
v1.0.0
initial
7 CVEs
CVE-2026-38532
GHSA-2xx8-j85v-j7wh
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38529
GHSA-r8rp-5f55-5j9x
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38527
GHSA-fpx9-9hq8-w2xc
Apr 14, 2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
8.5
/ 10
High
Network
Low
Low
None
Changed
High
Low
None
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-38530
GHSA-rm5f-3c25-p4cw
Apr 14, 2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References Updated Apr 16, 2026 · Source: OSV.dev
CVE-2026-5370
GHSA-9m2v-hc5g-5jpv
Apr 02, 2026
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Low
Network
Low
Low
A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function composeMail of the file packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts of the component Activities Module/Notes Module. The manipulation leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. The identifier of the patch is 73ed28d466bf14787fdb86a120c656a4af270153. To fix this issue, it is recommended to deploy a patch. Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
+ 16 more Show less
v1.3.1
v2.0.0
v2.0.0-BETA-1
v2.0.1
v2.0.2
v2.0.4
v2.0.5
v2.0.6
v2.1.0
v2.1.1
v2.1.2
v2.1.3
v2.1.4
v2.1.5
v2.1.6
v2.2.0
References
Updated Apr 04, 2026 · Source: OSV.dev
CVE-2024-45932
GHSA-74q2-6jp4-3rqq
Oct 07, 2024
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Medium
Network
Low
High
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
v1.2.2
v1.2.3
v1.2.4
v1.3.0
References Updated Oct 07, 2024 · Source: OSV.dev
CVE-2021-41924
GHSA-v829-j9rr-85v9
Jun 22, 2022
Cross-site Scripting in krayin/laravel-crm
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Webkul krayin crm before 1.2.2 is vulnerable to Cross Site Scripting (XSS). Affected versions
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.2.0
v1.2.1
Fixed in
1.2.2
References Updated Nov 08, 2023 · Source: OSV.dev |