VYPR
Medium severity4.3NVD Advisory· Published Oct 8, 2026· Updated Oct 8, 2026

CVE-2026-105831

CVE-2026-105831

Description

EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.

Affected products

2
  • Espocrm/Espocrmllm-fuzzy2 versions
    <10.0.6+ 1 more
    • (no CPE)range: <10.0.6
    • (no CPE)range: <10.0.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.