Webkul
Webkul Krayin CRM: vulnerabilidades y CVE
Webkul Krayin CRM tiene 17 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE17
Últimos 12 meses12
Críticas2
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-48543 | Media (5.1) | 0.14% | — | 24 sept 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template… |
| CVE-2026-48542 | Media (5.1) | 0.14% | — | 24 sept 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template… |
| CVE-2026-48541 | Media (5.1) | 0.14% | — | 24 sept 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template… |
| CVE-2026-48540 | Media (5.1) | 0.17% | — | 24 sept 2026 | Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template… |
| CVE-2026-90944 | Alta (8.8) | 0.66% | — | 14 sept 2026 | Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC… |
| CVE-2026-41453 | Alta (8.7) | 0.50% | — | 3 ago 2026 | Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the… |
| CVE-2026-36341 | Media (5.4) | 0.30% | — | 7 may 2026 | Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint |
| CVE-2026-38532 | Alta (8.1) | 0.41% | — | 14 abr 2026 | A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact… |
| CVE-2026-38530 | Alta (8.1) | 0.41% | — | 14 abr 2026 | A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead… |
| CVE-2026-38529 | Alta (8.8) | 0.84% | — | 14 abr 2026 | A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover… |
| CVE-2026-38527 | Alta (8.5) | 0.33% | — | 14 abr 2026 | A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request. |
| CVE-2026-38526 | Crítica (9.9) | 2.4% | — | 14 abr 2026 | An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file. |
| CVE-2025-3568 | Media (5.1) | 0.42% | — | 14 abr 2025 | A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File… |
| CVE-2024-45932 | Media (4.8) | 0.42% | — | 7 oct 2024 | Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2. |
| CVE-2024-46367 | Crítica (9.6) | 0.53% | — | 27 sept 2024 | A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to… |
| CVE-2024-46366 | Alta (8.8) | 0.53% | — | 27 sept 2024 | A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process.… |
| CVE-2023-2925 | Media (5.4) | 0.59% | — | 27 may 2023 | A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.