CVE-2026-66028
- EPSS 0.32%
- Veröffentlicht 27.07.2026 18:17:00
- Zuletzt bearbeitet 28.07.2026 20:37:39
Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit t...
CVE-2026-66029
- EPSS 0.17%
- Veröffentlicht 27.07.2026 18:17:00
- Zuletzt bearbeitet 28.07.2026 16:07:15
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit ...
CVE-2026-66030
- EPSS 0.17%
- Veröffentlicht 27.07.2026 18:17:00
- Zuletzt bearbeitet 28.07.2026 20:37:39
Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Cre...
CVE-2026-66031
- EPSS 0.17%
- Veröffentlicht 27.07.2026 18:09:41
- Zuletzt bearbeitet 28.07.2026 20:37:39
Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers ...
CVE-2025-40990
- EPSS 0.19%
- Veröffentlicht 02.10.2025 11:15:29
- Zuletzt bearbeitet 08.10.2025 20:45:17
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_bug/create/xxx", affecting to "title" and "description" parameters via POST. Thi...
CVE-2025-40991
- EPSS 0.19%
- Veröffentlicht 02.10.2025 11:15:29
- Zuletzt bearbeitet 08.10.2025 20:45:24
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_file/upload/xxxx", affecting to "description" parameter via POST. This vulnerabi...
CVE-2025-40989
- EPSS 0.19%
- Veröffentlicht 02.10.2025 11:15:28
- Zuletzt bearbeitet 08.10.2025 20:45:05
Stored Cross Site Scripting vulnerability in Ekushey CRM v5.0 by Creativeitem, due to lack of proper validation of user inputs via the "/ekushey/index.php/client/project_message/add/xxx", affecting to "message" parameter via POST. This vulnerability ...