PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66030 Creativeitem CVE debrief

CVE-2026-66030 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. These scripts execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.

Vendor
Creativeitem
Product
Ekushey Project Manager CRM
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Organizations using Ekushey Project Manager CRM version 5.0 or earlier should prioritize patching this vulnerability. Specifically, administrators and security teams responsible for client support systems should be aware of the potential for authenticated client users to inject malicious scripts.

Technical summary

The vulnerability exists in the Ticket Title field of the Create New Ticket page in Ekushey Project Manager CRM version 5.0. Authenticated client users can inject arbitrary HTML and JavaScript, which are then stored and executed in the browser sessions of Staff or Administrator users viewing the Client Support page. The CVSS score for this vulnerability is 5.1, indicating a medium severity level. This stored cross-site scripting vulnerability allows attackers to craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized. Organizations should prioritize patching this vulnerability, and implementing compensating controls such as input validation and output encoding may also be necessary until a patch is applied.

Defensive priority

Patching this vulnerability should be a priority for organizations using the affected version of Ekushey Project Manager CRM. Implementing compensating controls, such as input validation and output encoding, may also be necessary until a patch is applied.

Recommended defensive actions

  • Apply the vendor's official patch for Ekushey Project Manager CRM version 5.0 as soon as possible.
  • Implement input validation and output encoding for the Ticket Title field as a temporary measure.
  • Monitor for suspicious activity related to the Client Support page.
  • Educate client users about the risks of injecting malicious scripts.
  • Consider upgrading to a version of Ekushey Project Manager CRM that is not vulnerable.

Evidence notes

The CVE record was published on 2026-07-27T18:17:00.390Z and last modified on 2026-07-27T19:17:22.410Z. The NVD entry is currently in the 'Received' status. Multiple sources, including the vendor's disclosure and VulnCheck, have provided information about this vulnerability.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T18:17:00.390Z and has not been modified since then. The NVD entry is currently Received.