CVE-2026-26211
- EPSS 0.31%
- Veröffentlicht 25.08.2026 17:28:19
- Zuletzt bearbeitet 24.09.2026 20:43:32
Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element, the title e...
CVE-2026-66028
- EPSS 0.32%
- Veröffentlicht 27.07.2026 18:17:00
- Zuletzt bearbeitet 28.07.2026 20:37:39
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit t...
CVE-2026-66029
- EPSS 0.17%
- Veröffentlicht 27.07.2026 18:17:00
- Zuletzt bearbeitet 28.07.2026 16:07:15
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit ...
CVE-2026-66030
- EPSS 0.17%
- Veröffentlicht 27.07.2026 18:17:00
- Zuletzt bearbeitet 28.07.2026 20:37:39
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Cre...
CVE-2026-66031
- EPSS 0.17%
- Veröffentlicht 27.07.2026 18:09:41
- Zuletzt bearbeitet 28.07.2026 20:37:39
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers ...
CVE-2025-40990
- EPSS 0.19%
- Veröffentlicht 02.10.2025 11:15:29
- Zuletzt bearbeitet 30.09.2026 23:10:00
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_bug/create/xxx", affecting to "title" and "description" parameters via POST. Thi...
CVE-2025-40991
- EPSS 0.19%
- Veröffentlicht 02.10.2025 11:15:29
- Zuletzt bearbeitet 08.10.2025 20:45:24
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerabi...
CVE-2025-40989
- EPSS 0.19%
- Veröffentlicht 02.10.2025 11:15:28
- Zuletzt bearbeitet 08.10.2025 20:45:05
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability ...