CVE-2026-100882 | Krayin laravel-crm up to 2.2.5 Admin Settings Endpoint index.blade.php general.settings.footer.label cross site scripting (Issue 2622)
A vulnerability identified as problematic has been detected in Krayin laravel-crm up to 2.2.5. Impacted is an unknown function of the file packages/Webkul/Admin/src/Resources/views/components/layouts/index.blade.php of the component Admin Settings Endpoint. Performing a manipulation of the argument general.settings.footer.label results in cross site scripting.
This vulnerability is identified as CVE-2026-100882. The attack can be initiated remotely. Additionally, an exploit exists.
You should upgrade the affected component.VulDB Recent EntriesRead More