CVE-2026-36341: XSS
Published May 7, 2026
·Updated
Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
Affected Software
1 affected component
Webkul krayin crm=2.1.5
Event History
May 7, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-36341?
CVE-2026-36341 is classified as a high severity Cross-Site Scripting (XSS) vulnerability.
2
How do I fix CVE-2026-36341?
To fix CVE-2026-36341, upgrade Webkul Krayin CRM to version 2.1.6 or later.
3
What are the potential impacts of CVE-2026-36341?
CVE-2026-36341 could allow attackers to execute arbitrary JavaScript in users' browsers, compromising their sessions or data.
4
Which software is affected by CVE-2026-36341?
CVE-2026-36341 specifically affects Webkul Krayin CRM version 2.1.5.
5
Where does the vulnerability occur in CVE-2026-36341?
The vulnerability occurs in the comment field during Activity creation at the /admin/activities/create endpoint.