Unknown · Ekushey Project Manager Crm · CVE-2026-26211
**Name of the Vulnerable Software and Affected Versions**
Ekushey Project Manager CRM (affected versions not specified)
**Description**
The software fails to apply output encoding to the administrator-configured system name when it is written to the login page. This value is displayed in the description meta element, the title element, and an h4 element in the page header. Because the h4 element is parsed as markup, HTML injected into the system name field is rendered, allowing any associated event handlers to execute. Since the login page is accessible without authentication, the stored script executes in the browser of all visitors, including unauthenticated users, within the origin of the login form and adjacent to credential fields.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.