Stored HTML Injection in EspoCRM Product by EspoCRM
CVE-2026-105831
5.3MEDIUM
What is CVE-2026-105831?
EspoCRM versions prior to 10.0.6 are susceptible to a stored HTML injection vulnerability. This issue arises when unauthenticated attackers can submit specially crafted data through the Lead Capture public form. The crafted input is improperly stored in the LeadCaptureLogRecord.data, leading to unescaped HTML rendering when administrators access the logs. Although the Content Security Policy mitigates potential JavaScript execution, the vulnerability still poses risks by allowing attackers to inject malicious HTML content.
Affected Version(s)
espocrm 0 < 10.0.6
espocrm 10.0.6
