PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-97897 Krayin CVE debrief

A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345.

Vendor
Krayin
Product
laravel-crm
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-25
Original CVE updated
2026-09-25
Advisory published
2026-09-25
Advisory updated
2026-09-25

Who should care

Defenders responsible for Krayin laravel-crm deployments should assess exposure and prioritize upgrading to version 2.2.6 or later. This includes reviewing the official advisory, applying the patch, and monitoring for potential attacks. Security teams and vulnerability management teams should also review the affected component and plan for updates or mitigations through normal change control where exposure is confirmed. Additionally, operators and platform

Why it matters

Defenders should prioritize upgrading Krayin laravel-crm to version 2.2.6 or later to address the cross-site scripting vulnerability.

  • Potential cross-site scripting attacks via TinyMCE Media Upload
  • Need to verify affected versions and systems
  • Priority on upgrading to version 2.2.6 or later
  • Monitoring for potential attacks

Technical summary

The vulnerability affects Krayin laravel-crm up to 2.2.5, specifically in the TinyMCE Media Upload component of the Sanitizer.php file, allowing for cross-site scripting. The attack may be performed from remote locations. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. Defenders should assess exposure and prioritize upgrading to version 2.2.6 or later. The CVE record and source references provide information about the vulnerability, but further verification of affected versions and systems is required.

Defensive priority

Defenders should prioritize upgrading the affected component to version 2.2.6 or later.

Recommended defensive actions

  • Upgrade the affected component to version 2.2.6 or later
  • Review and apply the patch 734aa10ae6c2ffa4c96c8869a89aa66940e4d345
  • Monitor for potential cross-site scripting attacks
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record and source references provide information about the vulnerability in Krayin laravel-crm up to 2.2.5, affecting the TinyMCE Media Upload component, allowing for cross-site scripting. However, the scope of affected versions and systems requires further verification by defenders, who should check for exposure, review the official advisory, and apply the patch 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. Evidence limits suggest that additional details may exist but are not currently verified.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-97897 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-97897

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-97897 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-97897

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.