Webkul · Notes Module · CVE-2026-5370
Name of the Vulnerable Software and Affected Versions
krayin laravel-crm versions up to 2.2
Description
A cross-site scripting issue was identified in the `composeMail` function within the `packages/Webkul/Admin/tests/e2e-pw/tests/mail/inbox.spec.ts` file of the Activities Module/Notes Module. This manipulation can be exploited remotely, and a public exploit is available.
Recommendations
Deploy patch 73ed28d466bf14787fdb86a120c656a4af270153.