Ekushey Project Manager CRM stores the administrator-configured system name and writes it to the login page without output encoding. The value is emitted in three places on that page: the content attribute of the description meta element, the title element, and the text of an h4 element in the page header. The h4 occurrence is parsed as markup, so HTML placed in the system name field is rendered as markup and any event handler it carries runs. The login page is served without authentication, so the stored value executes in the browser of every visitor who loads it, including visitors who are not signed in, within the origin that serves the login form and alongside the credential fields on it. Storing the value requires an administrator session; the resulting script runs for unauthenticated visitors and persists until the setting is changed.
CVE-2026-26211
Score 4.8 from GitHub Security Advisory published 2026-08-25. a secondary CVSS source baseline 4.8; sources differ by 0.0.
- Lower severity and no public exploit yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 4.8
- EG Score
- 4.8(high)
- EG Risk
- 26(Track)EG Risk 26/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity48% × 45%Exploitation0% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS PROB
- 0%
- EPSS %ILE
- 23%
- KEV
- Not listed
Published
August 25, 2026
Last Modified
August 25, 2026
Advisory Details (2)
Auto-updated Aug 25, 2026Ekushey Project Manager CRM 5.0 Stored XSS via System Name Field | Advisories | VulnCheck
https://www.vulncheck.com/advisories/ekushey-project-manager-crm-5.0-stored-xss-via-system-name-fieldGitHub - LindHunt/CVE-2026-26211: Public disclosure for CVE-2026-26211, a stored XSS vulnerability affecting Ekushey Project Manager CRM v5.0. · GitHub
https://github.com/LindHunt/CVE-2026-26211Vendor Advisories for CVE-2026-26211(1)
These vendors published their own advisory mentioning this CVE — often with vendor-specific remediation steps + affected product lists not in NVD.
Weakness Classification(1)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 14× in last 7d / 14× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-08-30 01:22 UTCEPSS rescore
- 2026-08-29 13:14 UTCEG score recompute
- 2026-08-29 13:14 UTCGHSA enrichment
- 2026-08-28 21:41 UTCEPSS rescore
- 2026-08-28 14:45 UTCGHSA enrichment
- 2026-08-27 16:12 UTCEG score recompute
- 2026-08-27 16:12 UTCGHSA enrichment
- 2026-08-27 14:25 UTCEPSS rescore
- 2026-08-26 17:46 UTCEG score recompute
- 2026-08-26 17:46 UTCGHSA enrichment
- 2026-08-26 14:46 UTCEPSS rescore
- 2026-08-25 18:28 UTCEG score recompute
- 2026-08-25 17:40 UTCEG score recompute
- 2026-08-25 17:39 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Frequently asked(5)
What is CVE-2026-26211?
When was CVE-2026-26211 disclosed?
Is CVE-2026-26211 actively exploited?
What is the CVSS score of CVE-2026-26211?
How do I remediate CVE-2026-26211?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-26211
Is Your Infrastructure Affected by CVE-2026-26211?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.