Webkul Vulnerabilities and Affected Products
Vulnerabilities associated with Krayin CRM.
Products
Clear product- QloApps5 vulnerabilities
- Bagisto3 vulnerabilities
- krayin_crm3 vulnerabilities
- Krayin CRM2 vulnerabilities
- Ajax Quiz1 vulnerability
- Medical Prescription Attachment Plugin for WooCommerce1 vulnerability
- uvdesk1 vulnerability
- WooCommerce Point of Sale1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-3568MEDIUM | Webkul Krayin CRM SVG File edit cross site scriptingA vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The vendor prepares a fix for the next major release and explains that he does not think therefore that this should qualify … | CVSS5.1v4.0 | EPSS0.383% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
Webkul krayin crm Edit Person Page 2 cross site scriptingA vulnerability, which was classified as problematic, was found in Webkul krayin crm 1.2.4. This affects an unknown part of the file /admin/contacts/organizations/edit/2 of the component Edit Person Page. The manipulation of the argument Organization leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230079. NOTE: The vendor was contacted early about th… CWE-79May 27, 2023 | CVSS2.4v3.1 | EPSS0.592% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |