Skip to content

Vulnerabilities published by Secur0

Explore the list of CVEs reported through Secur0's programs. Check technical details and vulnerability statuses.

CVE-2026-78365

IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification

Critical
CVE-2026-19871

Use of hard-coded credentials in Prospero Flow CRM allows access to employee accounts created through the onboarding flow

Critical
CVE-2026-90896

Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII

High
CVE-2026-77759

IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records

High
CVE-2026-19870

IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation

High
CVE-2026-19734

IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking

High
CVE-2026-19539

IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion

High
CVE-2026-19433

Authorization Bypass Through User-Controlled Key in Prospero Flow CRM allows writing and reading other companies' contacts

High
CVE-2026-59233

Missing Authorization in Prospero Flow CRM allows any authenticated user to escalate privileges via the permission save endpoint

High
CVE-2026-59239

Stored XSS in Prospero Flow CRM email body allows administrator account takeover

High
CVE-2026-59235

Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts

High
CVE-2026-13164

Unauthenticated self-registration in MailerUp allows access to stored email data

High
CVE-2026-82911

CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes

Medium
CVE-2026-81931

Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting

Medium
CVE-2026-78337

Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG

Medium
CVE-2026-77780

Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers

Medium
CVE-2026-76203

CSS sanitizer bypass in Pentestify report themes allows forced outbound requests from users' browsers

Medium
CVE-2026-75872

HTML Injection in MailerUp allows attacker-controlled HTML to be delivered in double opt-in verification emails

Medium
CVE-2026-19744

Stored Cross-site Scripting in Pentestify allows JavaScript execution via Markdown links in report fields

Medium
CVE-2026-19716

Stored Cross-site Scripting in Pentestify user account deletion via unescaped username

Medium
CVE-2026-19434

Stored Cross-site Scripting in Pentestify allows JavaScript execution via the finding severity field

Medium
CVE-2026-59232

Stored Cross-site Scripting in Prospero Flow CRM allows JavaScript execution via the lead form name field

Medium
CVE-2026-59231

Server-Side Request Forgery in Pentestify allows authenticated users to trigger outbound server requests via unvalidated image URLs

Medium
CVE-2026-59240

IDOR in Prospero Flow CRM allows deletion of other users notifications

Medium
CVE-2026-59238

Stored XSS in Pentestify via unsanitized finding images and report client logo

Medium
CVE-2026-59237

IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders

Medium
CVE-2026-59236

Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection

Medium
CVE-2026-59234

IDOR in Prospero Flow CRM allows deletion of other users' calendar events

Medium
CVE-2026-13163

Lack of input validation in Mailerup input parameter leads to Open Redirect

Medium
CVE-2026-13150

SSRF in Pentestify PDF generation endpoint via crafted Host header

Medium

Found a vulnerability? Learn more in our Disclosure policy