PT-2026-99095 · Unknown · Krayin Laravel Crm

·

CVE-2026-97896

·

Published

2026-09-25

·

Updated

2026-09-25

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions krayin laravel-crm versions prior to 2.2.6
Description A remote cross-site scripting issue exists within the Upload Functionality component. The flaw is located in the ConfigurationForm::rules function of the packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php file, where improper manipulation allows for the execution of malicious scripts.
Recommendations Upgrade to version 2.2.6.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-97896

Affected Products

Krayin Laravel Crm