CVE-2026-105831: EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form

Published Oct 8, 2026
·
Updated

EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.

Affected Software

1 affected component
EspoCRM EspoCRM<10.0.6

Event History

Oct 8, 2026
CVE Published
via MITRE·02:10 PM
Data Sourced
via MITRE·02:10 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·03:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Instances that expose a Lead Capture public form are exposed because an unauthenticated attacker can submit crafted form data. The injected content is encountered when an administrator views the associated Lead Capture log record.

2

What must an attacker do to exploit it?

The attacker needs to submit crafted data through a Lead Capture public form. No authentication is required, but an administrator must later view the stored log record for the injected HTML to be rendered.

3

Does this lead to JavaScript execution?

The available information states that Content Security Policy blocks JavaScript execution. The documented impact is stored HTML injection and integrity impact, rather than JavaScript execution.

4

How can I determine whether an instance may already contain injected content?

Review Lead Capture log records, specifically the stored LeadCaptureLogRecord.data content, for unexpected HTML submitted through public forms. The vulnerable rendering occurs when administrators view those records.

5

What version addresses the issue?

Upgrade to EspoCRM 10.0.6 or later. Versions before 10.0.6 are affected according to the provided information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203