CVE-2026-19966: Codecanyon Timecamp Integration For CRM
Medium severity, CVSS 5.4. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown processing of the file /clients/save_contact of the component Contact Information Update. Such manipulation of the argument contact_id leads to authorization bypass. The attack can be launched remotely. The exploit is publicly available and might be used.
Affected products
- Codecanyon Timecamp Integration For CRM: version 2.0 only; version 2.1 only; version 2.2 only; version 2.3 only; version 2.4 only; version 2.5 only; …
Published 2026-08-17. Last modified 2026-08-20.