Description
EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.
Published: 2026-10-08
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Stored HTML Injection via unauthenticated lead capture form
Action: Patch
AI Analysis

Impact

EspoCRM versions prior to 10.0.6 store the raw contents of data submitted through the public lead capture form in a LeadCaptureLogRecord. When administrators view the log, this data is rendered unescaped, allowing an attacker to inject arbitrary HTML elements. Although the default Content Security Policy in recent deployments prevents the execution of malicious JavaScript, the injection still permits content tampering, potential phishing attempts, and defacement visible to privileged users.

Affected Systems

EspoCRM, all releases before version 10.0.6. The vulnerability applies to any instance that has the public lead capture form enabled, regardless of the specific deployment configuration.

Risk and Exploitability

The vulnerability has a CVSS score of 5.3, indicating moderate severity. No EPSS score is available, and the flaw is not listed in the CISAV catalog. The most straightforward attack is a web request to the exposed lead capture endpoint, which requires no authentication and can be performed by any Internet user. Because the input is stored and later displayed without proper escaping, the risk is limited to defacement or phishing rather than full code execution. However, the ease of exploitation and potential for persistent malicious content makes the attack vector significant for affected systems.

Generated by OpenCVE AI on October 8, 2026 at 15:56 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade EspoCRM to version 10.0.6 or later to eliminate the stored HTML injection flaw.
  • Ensure the Content Security Policy enforced by the application or web server disallows inline scripts and blocks JavaScript execution – for example, include "script-src 'none'" or a similarly restrictive directive.
  • Disable or remove the public lead capture form until the application can be patched, or configure it to sanitize or escape stored data before display.

Generated by OpenCVE AI on October 8, 2026 at 15:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 14:15:00 +0000

Type Values Removed Values Added
Description EspoCRM before 10.0.6 contains a stored HTML injection vulnerability that allows unauthenticated attackers to inject HTML by submitting crafted Lead Capture public form data. The request body is stored in LeadCaptureLogRecord.data and rendered unescaped when administrators view the log record, though Content Security Policy blocks JavaScript execution.
Title EspoCRM before 10.0.6 Unauthenticated Stored HTML Injection via Lead Capture Form
First Time appeared Espocrm
Espocrm espocrm
Weaknesses CWE-79
CPEs cpe:2.3:a:espocrm:espocrm:*:*:*:*:*:*:*:*
Vendors & Products Espocrm
Espocrm espocrm
References
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-10-08T17:52:27.189Z

Reserved: 2026-10-05T21:59:09.591Z

Link: CVE-2026-105831

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-08T15:17:35.507

Modified: 2026-10-08T15:17:35.643

Link: CVE-2026-105831

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T16:00:06Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')