Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Prospero Flow CRM — Vulnerabilities & Security Advisories 19

All 19 CVE vulnerabilities found in Prospero Flow CRM, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities for Prospero Flow CRM, classified under the Cross-Site Scripting weakness type. The collection encompasses a range of injection flaws, including stored, reflected, and DOM-based variants, documented within the timeframe of available public advisories and researcher disclosures for this specific product lineage. Readers can utilize this index to track the vendor's response patterns to reported issues, analyze the prevalence and evolution of script injection weaknesses in their codebase, or review the complete vulnerability history to assess the overall security posture of the platform over time. By centralizing these entries, the page offers a consolidated view for security professionals aiming to evaluate risk exposure, compare remediation velocities across different releases, and identify recurring implementation errors that may indicate systemic development practice gaps. The data serves as a reference point for understanding how the software handles user input validation and output encoding, highlighting areas where the product has historically fallen short of secure coding standards. This aggregation supports threat modeling efforts by providing empirical evidence of past exploitability and patching timelines, enabling stakeholders to make informed decisions regarding deployment strategies and security monitoring configurations without relying on scattered individual bulletin reports.

Vendor: Roskus

CVE ID Title CVSS Severity Published
CVE-2026-82911 CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes CWE-352 5.1 Medium 2026-09-04
CVE-2026-81931 Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting CWE-434 4.8 Medium 2026-08-27
CVE-2026-78365 IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification CWE-639 9.3 Critical 2026-08-24
CVE-2026-78337 Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG CWE-434 4.8 Medium 2026-08-24
CVE-2026-77780 Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers CWE-639 5.3 Medium 2026-08-21
CVE-2026-77759 IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records CWE-639 8.7 High 2026-08-21
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding CWE-798 9.3 Critical 2026-08-14
CVE-2026-19870 IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation CWE-639 8.6 High 2026-08-14
CVE-2026-19734 IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking CWE-639 8.6 High 2026-08-13
CVE-2026-19539 IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion CWE-862 8.6 High 2026-08-11
CVE-2026-19433 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export CWE-639 8.6 High 2026-08-10
CVE-2026-59233 Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation CWE-639 8.7 High 2026-08-10
CVE-2026-59232 Stored Cross-site Scripting in Prospero Flow CRM lead name field CWE-79 5.3 Medium 2026-07-31
CVE-2026-59240 IDOR in Prospero Flow CRM allows deletion of other users' notifications CWE-639 6.9 Medium 2026-07-27
CVE-2026-59239 Stored XSS in Prospero Flow CRM email body allows administrator account takeover CWE-79 8.6 High 2026-07-27
CVE-2026-59237 IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders CWE-639 - - 2026-07-16
CVE-2026-59236 Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection CWE-639 - - 2026-07-15
CVE-2026-59235 Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts CWE-639 - - 2026-07-15
CVE-2026-59234 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion CWE-639 - - 2026-07-03

All 19 known CVE vulnerabilities affecting Prospero Flow CRM with full Chinese analysis, references, and POCs where available.