PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66029 Creativeitem CVE debrief

CVE-2026-66029 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Manage Clients or Manage Client Projects pages where client names are rendered unsanitized. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM.

Vendor
Creativeitem
Product
Ekushey Project Manager CRM
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of Ekushey Project Manager CRM through version 5.0 should be aware of this vulnerability and take steps to mitigate it. This includes applying patches or updates provided by the vendor, and ensuring that user input is properly sanitized. The vulnerability can be exploited by authenticated client users, and it allows for stored cross-site scripting attacks.

Technical summary

The vulnerability exists in the client Name field on the Edit Profile page of Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject arbitrary HTML and JavaScript without sanitization, allowing for stored cross-site scripting attacks. The vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. The affected product is Ekushey Project Manager CRM, and the vulnerability can be exploited by entering malicious payloads into the client Name field.

Defensive priority

Medium priority should be given to patching or mitigating this vulnerability, as it allows for stored cross-site scripting attacks.

Recommended defensive actions

  • Apply patches or updates provided by the vendor
  • Ensure that user input is properly sanitized
  • Monitor for suspicious activity on the Manage Clients and Manage Client Projects pages
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record was published on 2026-07-27T18:17:00.250Z and has not been modified since then. The NVD entry is currently Received. There is limited information available about the vulnerability, and defenders should verify the affected scope and severity with the vendor. The vulnerability exists in Ekushey Project Manager CRM through version 5.0, and it allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T18:17:00.250Z and has not been modified since then.