VendorsWebkulkrayin_crmall versions
Vulnerabilities

Webkul Krayin CRM

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2024-46367
A Stored Cross-Site Scripting (XSS) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to inject arbitrary JavaScript code by submitting a malicious payload within the username field. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
Published 2024-09-27 · Analyzed
9.6EPSS 0.005
CVE-2026-38529
A Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily reset user passwords and perform a full account takeover via supplying a crafted HTTP request.
Published 2026-04-14 · Analyzed
8.8EPSS 0.006
CVE-2024-46366
A Client-side Template Injection (CSTI) vulnerability in Webkul Krayin CRM 1.3.0 allows remote attackers to execute arbitrary client-side template code by injecting a malicious payload during the lead creation process. This can lead to privilege escalation when the payload is executed, granting the attacker elevated permissions within the CRM system.
Published 2024-09-27 · Analyzed
8.8EPSS 0.005
CVE-2026-38530
A Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any lead owned by other users via supplying a crafted GET request.
Published 2026-04-14 · Analyzed
8.1EPSS 0.004
CVE-2026-38532
A Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php endpoint of Webkul Krayin CRM v2.2.x allows authenticated attackers to arbitrarily read, modify, and permanently delete any contact owned by other users via supplying a crafted GET request.
Published 2026-04-14 · Analyzed
8.1EPSS 0.004
CVE-2024-45932
Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via the organization name field in /admin/contacts/organizations/edit/2.
Published 2024-10-07 · Modified
7.1EPSS 0.004
CVE-2023-2925
Webkul krayin crm Edit Person Page 2 cross site scripting
Published 2023-05-27 · Modified
5.4EPSS 0.006
CVE-2025-3568
Webkul Krayin CRM SVG File edit cross site scripting
Published 2025-04-14 · Analyzed
5.4EPSS 0.004