Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

laravel-crm — Vulnerabilities & Security Advisories 16

All 16 CVE vulnerabilities found in laravel-crm, with AI-generated Chinese analysis, references, and POCs.

This page documents known security vulnerabilities within the laravel-crm product, categorized by weakness type and associated tags. It aggregates reports covering security issues identified in the software from its initial release through the present day, ensuring a comprehensive historical record of its security posture. Visitors to this resource can track official advisories issued by the vendor to stay informed about critical patches and mitigation strategies. Furthermore, users can gain a deeper understanding of specific weakness classes affecting the application, such as SQL injection or cross-site scripting, by examining how these flaws manifest in real-world scenarios. The page also serves as a lookup tool for the product’s vulnerability history, allowing developers and security analysts to review past incidents and assess the long-term impact of various security flaws. This aggregated data provides context for understanding the evolution of security risks associated with laravel-crm, helping stakeholders make informed decisions about risk management and compliance. By centralizing this information, the page aims to reduce the time spent searching for disparate reports and offer a clear, structured view of the product’s security landscape over time. This approach supports both retrospective analysis and proactive security planning for organizations relying on this CRM solution.

Vendor: krayin

CVE ID Title CVSS Severity Published
CVE-2026-100885 Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization CWE-639 7.3 High 2026-09-27
CVE-2026-100884 Krayin laravel-crm attachment-download Endpoint acl.php resource injection CWE-99 4.3 Medium 2026-09-27
CVE-2026-100883 Krayin laravel-crm acl.php access control CWE-284 6.3 Medium 2026-09-27
CVE-2026-100882 Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting CWE-79 2.4 Low 2026-09-27
CVE-2026-97897 Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting CWE-79 3.5 Low 2026-09-25
CVE-2026-97896 krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting CWE-79 3.5 Low 2026-09-25
CVE-2026-97895 krayin laravel-crm User Management UserController.php privileges management CWE-269 6.3 Medium 2026-09-25
CVE-2026-48543 Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description CWE-79 5.4 Medium 2026-09-24
CVE-2026-48542 Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field CWE-79 5.4 Medium 2026-09-24
CVE-2026-48541 Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field CWE-79 5.4 Medium 2026-09-24
CVE-2026-48540 Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title CWE-79 5.4 Medium 2026-09-24
CVE-2026-90944 Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse CWE-306 8.2 High 2026-09-14
CVE-2026-41453 Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter CWE-89 8.8 High 2026-08-03
CVE-2026-41452 Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup CWE-306 9.8 Critical 2026-08-03
CVE-2026-61460 Krayin CRM Insecure Direct Object Reference via Controllers CWE-639 8.8 High 2026-07-10
CVE-2026-5370 krayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting CWE-79 3.5 Low 2026-04-02

All 16 known CVE vulnerabilities affecting laravel-crm with full Chinese analysis, references, and POCs where available.