VYPR

CRM

by Krayin

CVEs (1)

  • CVE-2026-41453Aug 3, 2026
    risk 0.00cvss epss 0.00

    Krayin CRM before 2.2.4 contains a blind SQL injection vulnerability in the leads DataGrid that allows authenticated users with leads access to inject arbitrary SQL into a HAVING clause by manipulating the rotten_lead[in] query parameter, which is concatenated without…