CVE-2026-48542

CVE-2026-48542 published: Krayin CRM through 2.2.6 contains a stored client-side template injection vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by injecting Vue.js template expressions into the product name field. Attack...

View full NVD advisory → ← Back to CVE watch