Krayin CRM v2.2.x was discovered to contain a SQL injection vulnerability via the rotten_lead parameter at /Lead/LeadDataGrid.php.Referenceshttps://github.com/krayin/laravel-crmhttps://github.com/TREXNEGRO/Security-Advisories/tree/main/CVE-2026-38528