Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 25/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web form description field. Attackers can craft a web form description containing… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 29/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the product name field. Attackers can craft a product name containing double-brace template… | |
| Aplazada | Media (5.1) | 0.14% | — | Webkul Krayin CRMAI | 24/9/2026 | 30/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person name field. Attackers can craft a person name containing double-brace template… | |
| Aplazada | Media (5.1) | 0.17% | — | Webkul Krayin CRMAI | 24/9/2026 | 24/9/2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attackers can craft a lead title containing double-brace template… | |
| Aplazada | Alta (8.8) | 0.66% | — | Webkul Krayin CRMAI | 14/9/2026 | 24/9/2026 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with forged sender information and headers to insert emails with any subject and body,… | |
| Aplazada | Alta (8.7) | 0.50% | — | Webkul Krayin CRMAI | 3/8/2026 | 9/9/2026 | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without parameterized binding directly into a havingRaw()… | |
| Aplazada | Media (5.4) | 0.30% | 💥 PoC | Webkul Krayin CRMAI | 7/5/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint | |
| Analizada | Alta (8.1) | 0.41% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request. | |
| Analizada | Alta (8.1) | 0.41% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request. | |
| Analizada | Alta (8.8) | 0.84% | — | Webkul Krayin CRM | 14/4/2026 | 17/6/2026 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request. | |
| Aplazada | Alta (8.5) | 0.33% | — | Webkul Krayin CRMAI | 14/4/2026 | 17/6/2026 | A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. | |
| Aplazada | Crítica (9.9) | 2.4% | 💥 Exploit | Webkul Krayin CRMAI | 14/4/2026 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (5.1) | 0.42% | 💥 PoC | Webkul Krayin CRM | 14/4/2025 | 17/6/2026 | A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The… | |
| Modificada | Media (4.8) | 0.42% | — | Webkul Krayin CRM | 7/10/2024 | 5/7/2026 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. | |
| Analizada | Crítica (9.6) | 0.53% | — | Webkul Krayin CRM | 27/9/2024 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the… | |
| Analizada | Alta (8.8) | 0.53% | — | Webkul Krayin CRM | 27/9/2024 | 17/6/2026 | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated… | |
| Modificada | Media (5.4) | 0.59% | — | Webkul Krayin CRM | 27/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack… |