VulnSea

Krayin has 8 CVEs on record. Disclosure cadence is accelerating: 8 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 8. The median CVSS is 5.4 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-79 (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.4
Publish → KEV
—
Last 90 days
8 prev 0

Products

  • laravel-crm 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

Krayin vulnerabilities

CVEs affecting Krayin, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-97896Low· 3.5
today

A vulnerability was identified in krayin laravel-crm up to 2.2.5

A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Function…

▾ Sunlitkrayin · laravel-crmvia NVD
CVE-2026-97895Medium· 6.3PoC
today

A vulnerability was determined in krayin laravel-crm up to 2.2.5

A vulnerability was determined in krayin laravel-crm up to 2.2.5. This affects an unknown part of the file packages/Webkul/Admin/src/Http/Controllers/Settings/UserController.php of the component User Management. Executing a manipulation …

▾ Twilightkrayin · laravel-crmvia NVD
CVE-2026-97897Low· 3.5
today

A security flaw has been discovered in Krayin laravel-crm up to 2.2.5

A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The atta…

▾ SunlitKrayin · laravel-crmvia NVD
CVE-2026-48542Medium· 5.4
yesterday

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the produc…

▾ Sunlitkrayin · laravel-crmvia NVD
CVE-2026-48543Medium· 5.4PoC
yesterday

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the web fo…

▾ Twilightkrayin · laravel-crmvia NVD
CVE-2026-48541Medium· 5.4
yesterday

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the person…

▾ Sunlitkrayin · laravel-crmvia NVD
CVE-2026-48540Medium· 5.4PoC
yesterday

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead t…

▾ Twilightkrayin · laravel-crmvia NVD
CVE-2026-90944High· 8.2PoC
1w ago

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox

Krayin CRM through 2.2.6 exposes the POST /admin/mail/inbound-parse endpoint without authentication, allowing unauthenticated attackers to inject arbitrary emails into the CRM inbox. Attackers can supply crafted RFC 2822 messages with fo…

▾ Midnightkrayin · laravel-crmEPSS 0.66%via NVD
Krayin vulnerabilities (CVEs) · VulnSea