Cross-Site Scripting Vulnerability in Webkul Krayin CRM by Webkul
CVE-2026-36341

5.4MEDIUM

Key Information:

Vendor

Webkul

Vendor
CVE Published:
7 May 2026

What is CVE-2026-36341?

A Cross-Site Scripting (XSS) vulnerability has been identified in Webkul Krayin CRM version 2.1.5. This flaw arises from the application's failure to properly sanitize user input in the comment field during activity creation on the /admin/activities/create endpoint. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session, potentially compromising user data and session integrity. Users of affected versions are advised to upgrade to the latest release where this issue has been addressed.

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.