PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-66030 Creativeitem CVE debrief

CVE-2026-66030 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. These scripts execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.

Vendor
Creativeitem
Product
Ekushey Project Manager CRM
CVSS
MEDIUM 5.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Organizations using Ekushey Project Manager CRM version 5.0 or earlier should prioritize patching this vulnerability. Specifically, administrators and security teams responsible for client support systems should be aware of the potential for authenticated client users to inject malicious scripts.

Technical summary

The vulnerability exists in the Ticket Title field of the Create New Ticket page in Ekushey Project Manager CRM version 5.0. Authenticated client users can inject arbitrary HTML and JavaScript, which are then stored and executed in the browser sessions of Staff or Administrator users viewing the Client Support page. The CVSS score for this vulnerability is 5.1, indicating a medium severity level. This stored cross-site scripting vulnerability allows attackers to craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized. Organizations should prioritize patching this vulnerability, and implementing compensating controls such as input validation and output encoding may also be necessary until a patch is applied.

Defensive priority

Patching this vulnerability should be a priority for organizations using the affected version of Ekushey Project Manager CRM. Implementing compensating controls, such as input validation and output encoding, may also be necessary until a patch is applied.

Recommended defensive actions

  • Apply the vendor's official patch for Ekushey Project Manager CRM version 5.0 as soon as possible.
  • Implement input validation and output encoding for the Ticket Title field as a temporary measure.
  • Monitor for suspicious activity related to the Client Support page.
  • Educate client users about the risks of injecting malicious scripts.
  • Consider upgrading to a version of Ekushey Project Manager CRM that is not vulnerable.

Evidence notes

The CVE record was published on 2026-07-27T18:17:00.390Z and last modified on 2026-07-27T19:17:22.410Z. The NVD entry is currently in the 'Received' status. Multiple sources, including the vendor's disclosure and VulnCheck, have provided information about this vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-66030 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-66030

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-66030 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-66030

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.