Home

Description

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint

PUBLISHED Reserved 2026-04-06 | Published 2026-05-07 | Updated 2026-05-07 | Assigner mitre

References

cyber.spool.co.jp/vulnerabilities/cve-2026-36341/ exploit

github.com/krayin/laravel-crm/releases/tag/v2.1.6

github.com/krayin/laravel-crm/pull/2401

drive.google.com/...d/1Y_WjD4Tiq_z7zQUlddFCFMDoyyN300r9/view

cyber.spool.co.jp/vulnerabilities/cve-2026-36341/

github.com/cybercrewinc/CVE-2026-36341

cve.org (CVE-2026-36341)

nvd.nist.gov (CVE-2026-36341)

Download JSON