CVE-2026-36341
medium
CVSS v3
5.4
CVSS v2
—
VIR risk
5.4
Description
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Predictions
Exploit likelihood
64%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
No vendor mitigations ingested yet for this CVE. The mitigation-content worker queues fetches as references arrive — check back in a few minutes, or see the references list below.
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Packagist | krayin/laravel-crm | =2.1.5 | |
| Packagist | krayin/laravel-crm | >=2.1.5,<2.1.6 | 2.1.6 |
| COMPOSER | krayin/laravel-crm | = 2.1.5 | 2.1.6 |
References
- https://github.com/advisories/GHSA-j822-46r5-h4qx
- https://cyber.spool.co.jp/vulnerabilities/cve-2026-36341/
- https://drive.google.com/file/d/1Y_WjD4Tiq_z7zQUlddFCFMDoyyN300r9/view
- https://github.com/cybercrewinc/CVE-2026-36341
- https://github.com/krayin/laravel-crm/pull/2401
- https://github.com/krayin/laravel-crm/releases/tag/v2.1.6
- https://nvd.nist.gov/vuln/detail/CVE-2026-36341
- https://github.com/krayin/laravel-crm/commit/fc467040de21803cb2b67c2229d2dfcf731d2d3e
- https://cyber.spool.co.jp/vulnerabilities/cve-2026-36341
- https://github.com/krayin/laravel-crm
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.