« Volver al listado

Webkul

Webkul Krayin CRM: vulnerabilidades y CVE

Webkul Krayin CRM tiene 17 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE17
Últimos 12 meses12
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-48543Media (5.1)0.14%—24 sept 2026
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template…
CVE-2026-48542Media (5.1)0.14%—24 sept 2026
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template…
CVE-2026-48541Media (5.1)0.14%—24 sept 2026
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template…
CVE-2026-48540Media (5.1)0.17%—24 sept 2026
Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template…
CVE-2026-90944Alta (8.8)0.66%—14 sept 2026
Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC…
CVE-2026-41453Alta (8.7)0.50%—3 ago 2026
Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the…
CVE-2026-36341Media (5.4)0.30%—7 may 2026
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
CVE-2026-38532Alta (8.1)0.41%—14 abr 2026
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact…
CVE-2026-38530Alta (8.1)0.41%—14 abr 2026
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead…
CVE-2026-38529Alta (8.8)0.84%—14 abr 2026
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover…
CVE-2026-38527Alta (8.5)0.33%—14 abr 2026
A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.
CVE-2026-38526Crítica (9.9)2.4%—14 abr 2026
An authenticated arbitrary file upload vulnerability in the /admin/tinymce/upload endpoint of Webkul Krayin CRM v2.2.x allows attackers to execute arbitrary code via uploading a crafted PHP file.
CVE-2025-3568Media (5.1)0.42%—14 abr 2025
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File…
CVE-2024-45932Media (4.8)0.42%—7 oct 2024
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
CVE-2024-46367Crítica (9.6)0.53%—27 sept 2024
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to…
CVE-2024-46366Alta (8.8)0.53%—27 sept 2024
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process.…
CVE-2023-2925Media (5.4)0.59%—27 may 2023
A vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1210 Exploitation of Remote Services6
  2. T1059.007 JavaScript4
  3. T1189 Drive-by Compromise4
  4. T1005 Data from Local System3
  5. T1078 Valid Accounts1
  6. T1090 Proxy1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Webkul