CVE-2026-97897 | Krayin laravel-crm up to 2.2.5 TinyMCE Media Upload Sanitizer.php cross site scripting
A vulnerability, which was classified as problematic, was found in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting.
This vulnerability was named CVE-2026-97897. The attack may be performed from remote. There is no available exploit.
You should upgrade the affected component.VulDB Recent EntriesRead More