VYPR

Krayin CRM

by Krayin

CVEs (2)

  • CVE-2026-41452Aug 3, 2026
    risk 0.00cvss epss 0.01

    Krayin CRM 2.2.4 contains a missing authentication vulnerability in the installer middleware that allows unauthenticated remote attackers to overwrite the primary administrator account by sending a crafted HTTP POST request with the X-Requested-With: XMLHttpRequest header to…

  • CVE-2026-61460Jul 10, 2026
    risk 0.00cvss epss 0.00

    Krayin CRM through 2.2.3 contains an insecure direct object reference vulnerability in LeadController, PersonController, OrganizationController, QuoteController, and ActivityController that allows authenticated users to edit, update, or delete records owned by other users.…