PatchSiren cyber security CVE debrief
CVE-2026-66030 Creativeitem CVE debrief
CVE-2026-66030 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. These scripts execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.
- Vendor
- Creativeitem
- Product
- Ekushey Project Manager CRM
- CVSS
- MEDIUM 5.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Organizations using Ekushey Project Manager CRM version 5.0 or earlier should prioritize patching this vulnerability. Specifically, administrators and security teams responsible for client support systems should be aware of the potential for authenticated client users to inject malicious scripts.
Technical summary
The vulnerability exists in the Ticket Title field of the Create New Ticket page in Ekushey Project Manager CRM version 5.0. Authenticated client users can inject arbitrary HTML and JavaScript, which are then stored and executed in the browser sessions of Staff or Administrator users viewing the Client Support page. The CVSS score for this vulnerability is 5.1, indicating a medium severity level. This stored cross-site scripting vulnerability allows attackers to craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized. Organizations should prioritize patching this vulnerability, and implementing compensating controls such as input validation and output encoding may also be necessary until a patch is applied.
Defensive priority
Patching this vulnerability should be a priority for organizations using the affected version of Ekushey Project Manager CRM. Implementing compensating controls, such as input validation and output encoding, may also be necessary until a patch is applied.
Recommended defensive actions
- Apply the vendor's official patch for Ekushey Project Manager CRM version 5.0 as soon as possible.
- Implement input validation and output encoding for the Ticket Title field as a temporary measure.
- Monitor for suspicious activity related to the Client Support page.
- Educate client users about the risks of injecting malicious scripts.
- Consider upgrading to a version of Ekushey Project Manager CRM that is not vulnerable.
Evidence notes
The CVE record was published on 2026-07-27T18:17:00.390Z and last modified on 2026-07-27T19:17:22.410Z. The NVD entry is currently in the 'Received' status. Multiple sources, including the vendor's disclosure and VulnCheck, have provided information about this vulnerability.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T18:17:00.390Z and has not been modified since then. The NVD entry is currently Received.