https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-38532/
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the...
CVE-2026-38532 Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php: A Broken Object-Level Authorization...
krayin crmwebkulbroken
https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-5370/
Krayin CRM is vulnerable to Cross-site Scripting (XSS) | GitLab Advisory Database (GLAD)
CVE-2026-5370 Krayin CRM is vulnerable to Cross-site Scripting (XSS): A vulnerability was identified in krayin laravel-crm up to 2.2. Impacted is the function...
cross site scripting
https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-38529/
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php...
CVE-2026-38529 Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php: A Broken Object-Level Authorization (BOLA)...
https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2026-38527/
Webkul Krayin CRM has Server-Side Request Forgery (SSRF) | GitLab Advisory Database (GLAD)
CVE-2026-38527 Webkul Krayin CRM has Server-Side Request Forgery (SSRF): A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of...
server side request forgery
https://advisories.gitlab.com/composer/krayin/laravel-crm/CVE-2024-45932/
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name | GitLab Advisory...
CVE-2024-45932 Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name: Krayin CRM v1.3.0 is vulnerable to Cross Site Scripting (XSS) via...