CVE-2026-61460 is an insecure direct object reference vulnerability in Krayin CRM through 2.2.3. Authenticated users can edit, update, or delete records owned by other users due to missing record-level ownership validation in edit, update, and destroy methods. This vulnerability exists in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController. Attackers can modif [truncated]
A cross site scripting vulnerability was identified in krayin laravel-crm up to 2.2 within the Activities Module/Notes Module, specifically in the composeMail function. Remote exploitation is possible. A patch, 73ed28d466bf14787fdb86a120c656a4af270153, is available. Users should review and deploy the patch through normal change control. This vulnerability has a CVSS score of 2 and a severity of LOW. The C [truncated]