VYPR
Vendor

Ekushey

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2018-18417MedOct 19, 2018
    risk 0.38cvss 5.4epss 0.02

    In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

  • CVE-2026-26211MedAug 25, 2026
    risk 0.31cvss 4.8epss

    Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element, the title element, and the text of an h4…

  • CVE-2026-66031MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Reply Ticket field. Attackers can craft and store malicious…

  • CVE-2026-66030MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the Ticket Title field on the Create New Ticket page.…

  • CVE-2026-66029MedJul 27, 2026
    risk 0.00cvss 5.4epss 0.00

    Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authenticated client users to inject arbitrary HTML and JavaScript by entering malicious payloads into the client Name field on the Edit Profile page without…

  • CVE-2026-66028MedJul 27, 2026
    risk 0.00cvss 6.7epss 0.00

    Ekushey Project Manager CRM through version 5.0 contains a missing uniqueness constraint vulnerability that allows authenticated administrators to create duplicate client accounts with identical email and password credentials. Attackers can exploit the lack of email field…