CVE-2026-97897
3.5 LOWpublic exploit availablePublished 2026-09-25 · Updated 2026-09-29
AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.
NVD description
A security flaw has been discovered in Krayin laravel-crm up to 2.2.5. This issue affects some unknown processing of the file Sanitizer.php of the component TinyMCE Media Upload. The manipulation results in cross site scripting. The attack may be performed from remote. Upgrading to version 2.2.6 is capable of addressing this issue. The patch is identified as 734aa10ae6c2ffa4c96c8869a89aa66940e4d345. You should upgrade the affected component.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:N
Weaknesses
CWE-79, CWE-94
Public exploit & PoC references
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/734aa10ae6c2ffa4c96c8869a89aa66940e4d345
- https://github.com/krayin/laravel-crm/pull/2639
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.md
All references
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.md
- https://github.com/krayin/laravel-crm/
- https://github.com/krayin/laravel-crm/commit/734aa10ae6c2ffa4c96c8869a89aa66940e4d345
- https://github.com/krayin/laravel-crm/pull/2639
- https://github.com/krayin/laravel-crm/releases/tag/v2.2.6
- https://vuldb.com/cve/CVE-2026-97897
- https://vuldb.com/submit/915413
- https://vuldb.com/vuln/409909
- https://vuldb.com/vuln/409909/cti
- https://github.com/carlosalbertotuma/advisory/blob/main/advisory-03-stored-xss-tinymce-media-upload.md
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- UNSCOREDCVE-2026-100174PoC
- LOWCVE-2026-100311PoC
- MEDIUMCVE-2026-100313PoC
- MEDIUMCVE-2026-100877PoC
- LOWCVE-2026-100880PoC
- LOWCVE-2026-100881PoC
- LOWCVE-2026-100882PoC
- LOWCVE-2026-100904
Related by shared AI tags and CWE weakness class. Browse the full archive.