Stored HTML Injection in EspoCRM Product by EspoCRM
CVE-2026-105831

5.3MEDIUM

Key Information:

Vendor

Espocrm

Status
Vendor
CVE Published:
8 October 2026

What is CVE-2026-105831?

EspoCRM versions prior to 10.0.6 are susceptible to a stored HTML injection vulnerability. This issue arises when unauthenticated attackers can submit specially crafted data through the Lead Capture public form. The crafted input is improperly stored in the LeadCaptureLogRecord.data, leading to unescaped HTML rendering when administrators access the logs. Although the Content Security Policy mitigates potential JavaScript execution, the vulnerability still poses risks by allowing attackers to inject malicious HTML content.

Affected Version(s)

espocrm 0 < 10.0.6

espocrm 10.0.6

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

LvShenlyl
.