Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

krayin — Vulnerabilities & Security Advisories 16

Browse all 16 CVE security advisories affecting krayin. AI-powered Chinese analysis, POCs, and references for each vulnerability.

This page aggregates known vulnerabilities associated with the krayin vendor, focusing specifically on common weakness classifications. It serves as a centralized repository for security researchers and developers seeking to understand the threat landscape surrounding krayin’s software ecosystem. The content collected here spans a wide range of vulnerability types, including but not limited to cross-site scripting, SQL injection, and authorization bypass flaws found within the krayin product line. The data covers reported security incidents from the early availability of the software through to recent disclosures, ensuring a comprehensive historical perspective on its security posture. This time range allows users to analyze trends in how vulnerabilities are discovered, patched, and disclosed over the life cycle of the application. Visitors to this page can effectively track the vendor’s advisory history to stay informed about emerging risks and mitigation strategies. It provides the opportunity to deeply understand specific weakness classes as they manifest within krayin’s codebase, offering context that generic databases often lack. Additionally, users can look up the complete vulnerability history of specific krayin products to assess long-term security stability and compliance requirements. This resource is designed to support proactive security management by consolidating fragmented data into a coherent view, enabling better decision-making for system administrators and security analysts who rely on krayin infrastructure.

Found 16 results / 16 Clear Filters
Top products by krayin: laravel-crm
CVE ID Title CVSS Severity Published
CVE-2026-100885 Krayin laravel-crm admin-config-setup API Endpoint CanInstall.php authorization — laravel-crm CWE-639 7.3 High 2026-09-27
CVE-2026-100884 Krayin laravel-crm attachment-download Endpoint acl.php resource injection — laravel-crm CWE-99 4.3 Medium 2026-09-27
CVE-2026-100883 Krayin laravel-crm acl.php access control — laravel-crm CWE-284 6.3 Medium 2026-09-27
CVE-2026-100882 Krayin laravel-crm Admin Settings Endpoint index.blade.php cross site scripting — laravel-crm CWE-79 2.4 Low 2026-09-27
CVE-2026-97897 Krayin laravel-crm TinyMCE Media Upload Sanitizer.php cross site scripting — laravel-crm CWE-79 3.5 Low 2026-09-25
CVE-2026-97896 krayin laravel-crm Upload Functionality ConfigurationForm.php rules cross site scripting — laravel-crm CWE-79 3.5 Low 2026-09-25
CVE-2026-97895 krayin laravel-crm User Management UserController.php privileges management — laravel-crm CWE-269 6.3 Medium 2026-09-25
CVE-2026-48543 Krayin CRM 2.2.6 Stored Template Injection XSS via Web Form Description — laravel-crm CWE-79 5.4 Medium 2026-09-24
CVE-2026-48542 Krayin CRM 2.2.6 Stored Template Injection XSS via Product Name Field — laravel-crm CWE-79 5.4 Medium 2026-09-24
CVE-2026-48541 Krayin CRM 2.2.6 Stored Template Injection XSS via Contact Name Field — laravel-crm CWE-79 5.4 Medium 2026-09-24
CVE-2026-48540 Krayin CRM 2.2.6 Stored Template Injection XSS via Lead Title — laravel-crm CWE-79 5.4 Medium 2026-09-24
CVE-2026-90944 Krayin CRM through 2.2.6 Unauthenticated Email Injection via inbound-parse — laravel-crm CWE-306 8.2 High 2026-09-14
CVE-2026-41453 Krayin CRM < 2.2.4 Blind SQL Injection via LeadDataGrid.php rotten_lead Parameter — laravel-crm CWE-89 8.8 High 2026-08-03
CVE-2026-41452 Krayin CRM 2.2.4 Missing Authentication via install/api/admin-config-setup — laravel-crm CWE-306 9.8 Critical 2026-08-03
CVE-2026-61460 Krayin CRM Insecure Direct Object Reference via Controllers — laravel-crm CWE-639 8.8 High 2026-07-10
CVE-2026-5370 krayin laravel-crm Activities Module/Notes inbox.spec.ts composeMail cross site scripting — laravel-crm CWE-79 3.5 Low 2026-04-02

This page lists every published CVE security advisory associated with krayin. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.