Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Prospero Flow CRM — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in Prospero Flow CRM, with AI-generated Chinese analysis, references, and POCs.

Vendor: Roskus

CVE IDTitleCVSSSeverityPublished
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding CWE-798 9.3 Critical2026-08-14
CVE-2026-19870 IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation CWE-639 8.6 High2026-08-14
CVE-2026-19734 IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking CWE-639 8.6 High2026-08-13
CVE-2026-19539 IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion CWE-862 8.6 High2026-08-11
CVE-2026-19433 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export CWE-639 8.6 High2026-08-10
CVE-2026-59233 Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation CWE-639 8.7 High2026-08-10
CVE-2026-59232 Stored Cross-site Scripting in Prospero Flow CRM lead name field CWE-79 5.3 Medium2026-07-31
CVE-2026-59240 IDOR in Prospero Flow CRM allows deletion of other users' notifications CWE-639 6.9 Medium2026-07-27
CVE-2026-59239 Stored XSS in Prospero Flow CRM email body allows administrator account takeover CWE-79 8.6 High2026-07-27
CVE-2026-59237 IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders CWE-639--2026-07-16
CVE-2026-59236 Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection CWE-639--2026-07-15
CVE-2026-59235 Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts CWE-639--2026-07-15
CVE-2026-59234 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion CWE-639--2026-07-03

All 13 known CVE vulnerabilities affecting Prospero Flow CRM with full Chinese analysis, references, and POCs where available.