PatchSiren cyber security CVE debrief
CVE-2026-66029 Creativeitem CVE debrief
CVE-2026-66029 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Manage Clients or Manage Client Projects pages where client names are rendered unsanitized. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM.
- Vendor
- Creativeitem
- Product
- Ekushey Project Manager CRM
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Users of Ekushey Project Manager CRM through version 5.0 should be aware of this vulnerability and take steps to mitigate it. This includes applying patches or updates provided by the vendor, and ensuring that user input is properly sanitized. The vulnerability can be exploited by authenticated client users, and it allows for stored cross-site scripting attacks.
Technical summary
The vulnerability exists in the client Name field on the Edit Profile page of Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject arbitrary HTML and JavaScript without sanitization, allowing for stored cross-site scripting attacks. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. The affected product is Ekushey Project Manager CRM, and the vulnerability can be exploited by entering malicious payloads into the client Name field.
Defensive priority
Medium priority should be given to patching or mitigating this vulnerability, as it allows for stored cross-site scripting attacks.
Recommended defensive actions
- Apply patches or updates provided by the vendor
- Ensure that user input is properly sanitized
- Monitor for suspicious activity on the Manage Clients and Manage Client Projects pages
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-27T18:17:00.250Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The vulnerability exists in Ekushey Project Manager CRM through version 5.0, and it allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T18:17:00.250Z and has not been modified since then.