Krayin laravel-crm

12 known vulnerabilities in Krayin laravel-crm, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-100885 CVSS 5.5 medium A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file…
  • CVE-2026-100884 CVSS 2.1 low A vulnerability has been found in Krayin laravel-crm up to 2.2.5. The impacted element is the function Storage::download of the file…
  • CVE-2026-100883 CVSS 2.1 low A flaw has been found in Krayin laravel-crm up to 2.2.5. The affected element is an unknown function of the file…
  • CVE-2026-100882 CVSS 1.9 low A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file…
  • CVE-2026-97897 CVSS 5.1 medium A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file…
  • CVE-2026-97896 CVSS 2.0 low A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the…
  • CVE-2026-97895 CVSS 2.1 low A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file…
  • CVE-2026-48543 CVSS 5.1 medium Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute…
  • CVE-2026-48542 CVSS 5.1 medium Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute…
  • CVE-2026-48541 CVSS 5.1 medium Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute…
  • CVE-2026-48540 CVSS 5.1 medium Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute…
  • CVE-2026-90944 CVSS 8.8 high Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to…