A vulnerability was found in Creativeitem Ekushey Project Manager CRM up to 5.0. It has been rated as problematic. Affected by this vulnerability is an unknown functionality of the component Ticket Title Field. The manipulation of the argument Ticket Title leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-66030. The attack is possible to be carried out remotely. No exploit exists.