CVE-2026-66030 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page. These scripts execute in the browser sessions of Staff or Administrator users who view the Client Support page where ticket titles are rendered unsanitized.
CVE-2026-66029 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM through version 5.0. Authenticated client users can inject HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without sanitization. Attackers can craft and store malicious scripts that execute in the browser sessions of Staff or Administrator users who view the M [truncated]
CVE-2026-66028 is a high-severity vulnerability in Ekushey Project Manager CRM. The vulnerability allows authenticated administrators to create duplicate client accounts with identical email and password credentials due to a missing uniqueness constraint. This can lead to unpredictable authentication behavior and unauthorized account access. The vulnerability affects Ekushey Project Manager CRM version 5. [truncated]