Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-105831— EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form

Quick assessment

Affected
espocrm espocrm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

EspoCRM 10.0.6 之前的版本存在一个存储型 HTML 注入漏洞,攻击者无需身份验证即可通过构造恶意数据提交到“潜在客户捕获”(Lead Capture)公共表单,从而注入 HTML 内容。这些请求体数据会被存储在 字段中,并在管理员查看日志记录时被未经转义地渲染出来。尽管内容安全策略(CSP)限制了 JavaScript 的执行,但 HTML 注入仍然可能发生。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-105831

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form
Source: CVE Program / CVE List V5
Vulnerability Description
EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
espocrm espocrm 0 ~ 10.0.6 -

II. Public POCs for CVE-2026-105831

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-105831

请登录查看更多情报信息。

Other References for CVE-2026-105831 (2)

Same Patch Batch · espocrm · 2026-10-08 · 3 CVEs total

CVE-2026-105833 7.7 HIGH EspoCRM before 10.0.5 IDOR via PersonalAccount Service Exposes IMAP Passwords
CVE-2026-105832 4.3 MEDIUM EspoCRM before 10.0.6 Two-Factor Authentication Bypass on Unauthenticated Routes

IV. Related Vulnerabilities

V. Comments for CVE-2026-105831

No comments yet


Leave a comment