Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
Modified: 4/16/2026
package
pkg:packagist/krayin/laravel-crm
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Contact/Persons/PersonController.php
Modified: 4/16/2026
Krayin CRM allows a remote attacker to execute arbitrary code via compose email function
Modified: 5/7/2026
Krayin CRM vulnerable to Cross Site Scripting (XSS) via the organization name
Modified: 10/7/2024
Krayin CRM is vulnerable to Cross-site Scripting (XSS)
Modified: 4/4/2026
Webkul Krayin CRM has Server-Side Request Forgery (SSRF)
Modified: 4/16/2026
Webkul Krayin CRM is Vulnerable to Cross-Site Scripting in the /admin/activities/create endpoint
Modified: 5/12/2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Settings/UserController.php
Modified: 4/16/2026
Webkul Krayin CRM has Broken Object-Level Authorization (BOLA) in the /Controllers/Lead/LeadController.php
Modified: 4/16/2026
Cross-site Scripting in krayin/laravel-crm
Modified: 11/8/2023