CVE-2026-48540

CVE-2026-48540 published: Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the lead title field. Attacker...

View full NVD advisory → ← Back to CVE watch