{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-105831", "assignerOrgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "state": "PUBLISHED", "assignerShortName": "VulnCheck", "dateReserved": "2026-10-05T21:59:09.591Z", "datePublished": "2026-10-08T14:10:31.635Z", "dateUpdated": "2026-10-08T17:52:27.189Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "83251b91-4cc7-4094-a5c7-464a1b83ea10", "shortName": "VulnCheck", "dateUpdated": "2026-10-08T14:10:31.635Z" }, "datePublic": "2026-09-21T00:00:00.000Z", "title": "EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form", "descriptions": [ { "lang": "en", "value": "EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution." } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "cweId": "CWE-79", "type": "CWE" } ] } ], "affected": [ { "vendor": "espocrm", "product": "espocrm", "defaultStatus": "unaffected", "versions": [ { "version": "0", "status": "affected", "versionType": "semver", "lessThan": "10.0.6" }, { "version": "10.0.6", "status": "unaffected", "versionType": "semver" } ] } ], "cpeApplicability": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*", "versionEndExcluding": "10.0.6" } ] } ] } ], "metrics": [ { "format": "CVSS", "cvssV4_0": { "version": "4.0", "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "attackRequirements": "NONE", "privilegesRequired": "NONE", "userInteraction": "PASSIVE", "vulnConfidentialityImpact": "NONE", "vulnIntegrityImpact": "LOW", "vulnAvailabilityImpact": "NONE", "subConfidentialityImpact": "NONE", "subIntegrityImpact": "NONE", "subAvailabilityImpact": "NONE", "baseScore": 5.3, "baseSeverity": "MEDIUM" } }, { "format": "CVSS", "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "NONE", "integrityImpact": "LOW", "availabilityImpact": "NONE", "baseScore": 4.3, "baseSeverity": "MEDIUM" } } ], "references": [ { "url": "https://github.com/espocrm/espocrm/security/advisories/GHSA-xfqv-j65r-qqgh", "tags": [ "vendor-advisory" ], "name": "GitHub Security Advisory (GHSA-xfqv-j65r-qqgh)" }, { "name": "VulnCheck Advisory: EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form", "tags": [ "third-party-advisory" ], "url": "https://www.vulncheck.com/advisories/espocrm-before-10.0.6-unauthenticated-stored-html-injection-via-lead-capture-form" } ], "credits": [ { "lang": "en", "value": "LvShenlyl", "type": "reporter" } ], "x_generator": { "engine": "vulncheck-endgame" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-10-08T15:35:56.106381Z", "id": "CVE-2026-105831", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-10-08T17:52:27.189Z" } } ] } }