---
id: CVE-2026-105831
title: >-
  EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that
  allows unauthenticated attackers to inject HTML by submitting crafted Lead
  Capture public form data
summary: >-
  EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that
  allows unauthenticated attackers to inject HTML by submitting crafted Lead
  Capture public form data. The request body is stored in
  LeadCaptureLogRecord.data and re…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'
cwe:
  - CWE-79
vendor: espocrm
product: espocrm
affected:
  - espocrm < 10.0.6
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T18:17:14.857'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105831'
references:
  - url: 'https://github.com/espocrm/espocrm/security/advisories/GHSA-xfqv-j65r-qqgh'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/espocrm-before-10.0.6-unauthenticated-stored-html-injection-via-lead-capture-form
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-08T15:35:56.106381Z'
ingestedAt: '2026-10-08T14:47:16.359Z'
---

## Overview

EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
