Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Prospero Flow CRM — Vulnerabilities & Security Advisories 15

All 15 CVE vulnerabilities found in Prospero Flow CRM, with AI-generated Chinese analysis, references, and POCs.

This page documents known security weaknesses affecting Prospero Flow CRM, a customer relationship management software solution. It aggregates vulnerability data related to this specific product, focusing on the structural flaws and implementation errors that expose the system to potential exploitation by malicious actors or unauthorized users. The collection covers a comprehensive range of Common Weakness Enumeration (CWE) classes, including but not limited to injection flaws, broken access controls, and security misconfigurations that have been identified in the software over time. The content spans from the earliest recorded instances of these security issues to the most recent updates, ensuring a continuous timeline of risk exposure. By maintaining this historical record, the page provides context on how vulnerabilities have evolved, persisted, or been remediated within the product’s development lifecycle. Readers can utilize this resource to track a vendor's advisories as they are released, gaining insight into the manufacturer's response time and transparency regarding security incidents. Additionally, users can understand a weakness class by examining how specific CWEs manifest in the context of CRM applications, observing patterns in code or configuration that lead to these defects. The page also allows users to look up a product's vulnerability history, offering a detailed view of past issues, their severity ratings, and the current status of any patches or workarounds. This structured approach supports security teams in conducting thorough risk assessments, prioritizing remediation efforts, and making informed decisions about the continued deployment or updating of Prospero Flow CRM within their organizations.

Vendor: Roskus

CVE IDTitleCVSSSeverityPublished
CVE-2026-77780 Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers CWE-639 5.3 Medium2026-08-21
CVE-2026-77759 IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records CWE-639 8.7 High2026-08-21
CVE-2026-19871 Use of hard-coded credentials in Prospero Flow CRM employee onboarding CWE-798 9.3 Critical2026-08-14
CVE-2026-19870 IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation CWE-639 8.6 High2026-08-14
CVE-2026-19734 IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking CWE-639 8.6 High2026-08-13
CVE-2026-19539 IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion CWE-862 8.6 High2026-08-11
CVE-2026-19433 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM contact save and vCard export CWE-639 8.6 High2026-08-10
CVE-2026-59233 Missing Authorization in Prospero Flow CRM permission save endpoint allows privilege escalation CWE-639 8.7 High2026-08-10
CVE-2026-59232 Stored Cross-site Scripting in Prospero Flow CRM lead name field CWE-79 5.3 Medium2026-07-31
CVE-2026-59240 IDOR in Prospero Flow CRM allows deletion of other users' notifications CWE-639 6.9 Medium2026-07-27
CVE-2026-59239 Stored XSS in Prospero Flow CRM email body allows administrator account takeover CWE-79 8.6 High2026-07-27
CVE-2026-59237 IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders CWE-639--2026-07-16
CVE-2026-59236 Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection CWE-639--2026-07-15
CVE-2026-59235 Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts CWE-639--2026-07-15
CVE-2026-59234 Authorization Bypass Through User-Controlled Key in Prospero Flow CRM calendar event deletion CWE-639--2026-07-03

All 15 known CVE vulnerabilities affecting Prospero Flow CRM with full Chinese analysis, references, and POCs where available.