CVE-2026-38527

HIGH

Webkul Krayin CRM 2.2.x - SSRF

Title source: llm

Description

A Server-Side Request Forgery (SSRF) in the /settings/webhooks/create component of Webkul Krayin CRM v2.2.x allows attackers to scan internal resources via supplying a crafted POST request.

Scores

CVSS v3 8.5
EPSS 0.0003
EPSS Percentile 9.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N

Details

CWE
CWE-918
Status published
Products (1)
krayin/laravel-crm 0Packagist
Published Apr 14, 2026
Tracked Since Apr 14, 2026