These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
A vulnerability was found in Krayin laravel-crm up to 2.2.4. This affects an unknown function of the file packages/Webkul/Installer/src/Http/Middleware/CanInstall.php of the component admin-config-setup API Endpoint. The manipulation results in authorization bypass. The attack may be launched remotely. The exploit has been made public and could be used. Upgrading to version 2.2.5 mitigates this issue.
A vulnerability was found in Krayin laravel-crm up to 2.2.5, affecting the attachment-download endpoint. The issue is due to improper control of resource identifiers in the Storage::download function. This vulnerability allows remote attackers to access unauthorized files. Upgrading to version 2.2.6 resolves this issue. The patch 13d6988cda8d69ece45ee1890effc90a7f21cdc1 has been applied to fix the vulnera [truncated]
A flaw in Krayin laravel-crm up to 2.2.5 allows improper access controls due to a manipulation in an unknown function of the file packages/Webkul/Admin/src/Config/acl.php. The attack can be launched remotely. Upgrading to version 2.2.6 is sufficient to fix this issue. This vulnerability affects Krayin laravel-crm instances, particularly those with remote access, and defenders should verify exposure and as [truncated]
A vulnerability was detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting. The attack can be initiated remotely. The exploit is now public and may be u [truncated]
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345.
A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Upgrading to [truncated]
A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation of the argument role_id can lead to improper privilege management. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. Upgrad [truncated]
CVE-2026-48543 is a stored client-side template injection vulnerability in Krayin CRM through version 2.2.6. Authenticated attackers can inject Vue.js template expressions into the web form description field, allowing execution of arbitrary JavaScript in other users' browsers when they view the affected web form. This vulnerability enables prototype chain traversal to retrieve the Function constructor and [truncated]
CVE-2026-41453 Krayin CRM blind SQL injection vulnerability debrief. The Krayin CRM before version 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid. Authenticated users with leads access can inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter. This allows attackers to extract the entire database contents, including user credential hashes, C [truncated]
CVE-2026-41452 is a critical vulnerability in Krayin CRM 2.2.4 that allows unauthenticated remote attackers to overwrite the primary administrator account. This is achieved by sending a crafted HTTP POST request to bypass the CanInstall middleware redirect check, enabling full administrative access to all CRM data. The vulnerability's impact includes potential data tampering or extraction, and requires ve [truncated]
CVE-2026-61460 is an insecure direct object reference vulnerability in Krayin CRM through 2.2.3. Authenticated users can edit, update, or delete records owned by other users due to missing record-level ownership validation in edit, update, and destroy methods. This vulnerability exists in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController. Attackers can modif [truncated]
A cross site scripting vulnerability was identified in krayin laravel-crm up to 2.2 within the Activities Module/Notes Module, specifically in the composeMail function. Remote exploitation is possible. A patch, 73ed28d466bf14787fdb86a120c656a4af270153, is available. Users should review and deploy the patch through normal change control. This vulnerability has a CVSS score of 2 and a severity of LOW. The C [truncated]