Vuln
·
Scope
首頁
套件
KEV
Critical
深度報告
EN
中
Loading…
Packagist/krayin/laravel-crm — 9 CVEs · VulnScope
pkg:Packagist/
krayin/laravel-crm
共 9 筆 CVE
HIGH
5
MEDIUM
3
LOW
1
✅ 檢查你的版本
檢查
所有已知漏洞
HIGH
8.8
CVE-2026-38529
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
from 0, <= 2.2.0
HIGH
8.5
CVE-2026-38527
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
from 0, <= 2.2.0
HIGH
8.1
CVE-2026-36340
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
>= 2.1.5, < 2.1.6
HIGH
8.1
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
from 0, <= 2.2.0
HIGH
8.1
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
from 0, <= 2.2.0
MEDIUM
6.1
Cross-site Scripting in krayin/laravel-crm
from 0, < 1.2.2
MEDIUM
5.4
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
>= 2.1.5, < 2.1.6
MEDIUM
4.8
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
from 0, <= 1.3.0
LOW
3.5
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
from 0, <= 2.2.0
CVE-2026-38532
CVE-2026-38530
CVE-2021-41924
CVE-2026-36341
CVE-2024-45932
CVE-2026-5370