CVE-2026-105831: Espocrm

Medium severity, CVSS 4.3. EPSS: 0.3% chance of exploitation in the next 30 days.

EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.

Affected products

  • Espocrm Espocrm: before 10.0.6 (fixed in 10.0.6)

Published 2026-10-08. Last modified 2026-10-08.