CVE-2026-105831: EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form
EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Instances that expose a Lead Capture public form are exposed because an unauthenticated attacker can submit crafted form data. The injected content is encountered when an administrator views the associated Lead Capture log record.
What must an attacker do to exploit it?
The attacker needs to submit crafted data through a Lead Capture public form. No authentication is required, but an administrator must later view the stored log record for the injected HTML to be rendered.
Does this lead to JavaScript execution?
The available information states that Content Security Policy blocks JavaScript execution. The documented impact is stored HTML injection and integrity impact, rather than JavaScript execution.
How can I determine whether an instance may already contain injected content?
Review Lead Capture log records, specifically the stored LeadCaptureLogRecord.data content, for unexpected HTML submitted through public forms. The vulnerable rendering occurs when administrators view those records.
What version addresses the issue?
Upgrade to EspoCRM 10.0.6 or later. Versions before 10.0.6 are affected according to the provided information.