Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activities/create endpoint
{
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/36xxx/CVE-2026-36341.json",
"cna_assigner": "mitre"
}