What is CVE-2026-66029?
CVE-2026-66029 is a stored cross-site scripting vulnerability in Ekushey Project Manager CRM up to version 5.0, allowing authenticated users to inject malicious scripts via the unsanitized Name field on the Edit Profile page. Immediate input sanitization and updating to the latest version are required to mitigate the risk.
Azərbaycanca: CVE-2026-66029, Ekushey Project Manager CRM-in 5.0 versiyasına qədər olan sistemlərində aşkarlanmış saxlanılan XSS zəifliyidir. Bu boşluq autentifikasiya olunmuş istifadəçilərə Profil redaktə səhifəsindəki Ad sahəsinə zərərli kod daxil etməyə imkan verir. Təcili olaraq daxiletmə sahələrində sanitizasiya tətbiq edilməli və CRM ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Ekushey
FAQ2
Does exploiting CVE-2026-66029 require authentication?
Yes, exploiting this stored XSS vulnerability requires the attacker to be an authenticated user. The malicious code is injected via the Name field on the Edit Profile page.
Which versions of Ekushey Project Manager CRM are vulnerable to CVE-2026-66029?
All versions of Ekushey Project Manager CRM up to version 5.0 are affected by this stored XSS vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.