Cross-Site Scripting Vulnerability in Webkul Krayin CRM by Webkul
CVE-2026-36341
5.4MEDIUM
What is CVE-2026-36341?
A Cross-Site Scripting (XSS) vulnerability has been identified in Webkul Krayin CRM version 2.1.5. This flaw arises from the application's failure to properly sanitize user input in the comment field during activity creation on the /admin/activities/create endpoint. An attacker could exploit this vulnerability to execute arbitrary JavaScript code in the context of the user's browser session, potentially compromising user data and session integrity. Users of affected versions are advised to upgrade to the latest release where this issue has been addressed.
