PULSE
FEED
ransomsilentransomgroup reclama a N... · Not Foundransomsilentransomgroup reclama a S... · Not Foundransommetaencryptor reclama a GE Vernova Inc. · US · Energy & Utilitiesransommetaencryptor reclama a PKF Hadiwinata · ID · Professional Servicesransommetaencryptor reclama a Platinum Healthcare Staffing · US · Healthcareransomemperador reclama a Electrolux & Ontrac · Manufacturingransomeverest reclama a Securitas Group · SE · Professional Servicesransomeverest reclama a Morula IVF · ZA · Healthcareransomwallstreet reclama a Tobin & Company · US · Financial Servicesransomwallstreet reclama a Ar Valve Resources · GB · Energy & Utilitiesransomwallstreet reclama a GTFM · US · Not Foundransomwallstreet reclama a Beatus Cartons · GB · Manufacturingransomeverest reclama a Reliance Audit · Professional Servicesransomeverest reclama a UNIRITA · JP · Technologyransomsilentransomgroup reclama a N... · Not Foundransomsilentransomgroup reclama a S... · Not Foundransommetaencryptor reclama a GE Vernova Inc. · US · Energy & Utilitiesransommetaencryptor reclama a PKF Hadiwinata · ID · Professional Servicesransommetaencryptor reclama a Platinum Healthcare Staffing · US · Healthcareransomemperador reclama a Electrolux & Ontrac · Manufacturingransomeverest reclama a Securitas Group · SE · Professional Servicesransomeverest reclama a Morula IVF · ZA · Healthcareransomwallstreet reclama a Tobin & Company · US · Financial Servicesransomwallstreet reclama a Ar Valve Resources · GB · Energy & Utilitiesransomwallstreet reclama a GTFM · US · Not Foundransomwallstreet reclama a Beatus Cartons · GB · Manufacturingransomeverest reclama a Reliance Audit · Professional Servicesransomeverest reclama a UNIRITA · JP · Technology
← All CVEs
CVE WatchSep 25, 2026

CVE-2026-97896

A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the fi

CVSS

3.5

Low

EPSS

—

KEV

—

Exploit Today

—

0-100

Published: Sep 25, 2026 · Last modified: Sep 25, 2026 · CWE-79 · CWE-94

EPSS · 30d

Not enough EPSS history yet.

Technical description

A vulnerability was identified in krayin laravel-crm up to 2.2.5. This vulnerability affects the function ConfigurationForm::rules of the file packages/Webkul/Admin/src/Http/Requests/ConfigurationForm.php of the component Upload Functionality. The manipulation leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Upgrading to version 2.2.6 is able to resolve this issue. The identifier of the patch is b9836530ec9f5ef0f51653bb0cbbc47ef7184f51. It is advisable to upgrade the affected component.

Official references
Related CVEs
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-967958.8 HIG
—
———Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0.3h
CVE-2026-71483—
—
———Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0.4h
CVE-2026-634326.5 MED
—
———Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /employee/get-employee-mail-preview with the full request object in the Django template context. An authenticated user with a valid CSRF token can use template attribute traversal to read request.user.password, request.META, and related-user attributes, exposing password hashes, personal data, and server request metadata. Django template restrictions prevent arbitrary code execution through this primitive, so the demonstrated impact is information disclosure and possible offline password cracking or account compromise. This issue is fixed in versions 1.6.0 and 2.0.0.4h
CVE-2026-100383—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - WikiLambda Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - WikiLambda Extension: 1.47.0-alpha. The issue has been remediated on the `master` branch.4h
CVE-2026-100381—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - UploadWizard Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - UploadWizard Extension: from * before 1.46.1, 1.45.5, 1.43.10.4h
CVE-2026-100380—
—
———Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - Wikibase Extension allows Cross-Site Scripting (XSS). This issue affects Mediawiki - Wikibase Extension: from * before 1.46.1, 1.45.5, 1.43.10.5h