Cross Site Scripting Vulnerability in Krayin Laravel CRM by Krayin
CVE-2026-97897

5.1MEDIUM

Key Information:

Vendor

Krayin

Vendor
CVE Published:
25 September 2026

What is CVE-2026-97897?

A security flaw has been identified in Krayin's Laravel CRM, affecting versions up to 2.2.5, where the TinyMCE Media Upload component's Sanitizer.php file is susceptible to a cross-site scripting attack. This vulnerability can be leveraged by an attacker via remote exploitation, potentially compromising user data. Affected users are strongly encouraged to update to version 2.2.6 or later, which addresses this issue with a patch identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345, to ensure the security of their systems.

Affected Version(s)

laravel-crm 2.2.0

laravel-crm 2.2.1

laravel-crm 2.2.2

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bl4dsc4n (VulDB User)
.