Vulnerabilities published by Secur0
Explore the list of CVEs reported through Secur0's programs. Check technical details and vulnerability statuses.
CVE-2026-78365
IDOR and missing authorization in Prospero Flow CRM supplier API allows cross-tenant read and modification
Critical
CVE-2026-19871
Use of hard-coded credentials in Prospero Flow CRM allows access to employee accounts created through the onboarding flow
Critical
CVE-2026-90896
Missing authentication in Ecommerce Template checkout session endpoint allows unauthenticated disclosure of buyer PII
High
CVE-2026-77759
IDOR and missing authorization in the Prospero Flow CRM transaction API allow cross-tenant reading of financial records
High
CVE-2026-19870
IDOR in Prospero Flow CRM allows cross-tenant payroll disclosure and creation
High
CVE-2026-19734
IDOR in Prospero Flow CRM allows cross-tenant product disclosure and hijacking
High
CVE-2026-19539
IDOR in Prospero Flow CRM allows cross-tenant ticket read, hijacking, and deletion
High
CVE-2026-19433
Authorization Bypass Through User-Controlled Key in Prospero Flow CRM allows writing and reading other companies' contacts
High
CVE-2026-59233
Missing Authorization in Prospero Flow CRM allows any authenticated user to escalate privileges via the permission save endpoint
High
CVE-2026-59239
Stored XSS in Prospero Flow CRM email body allows administrator account takeover
High
CVE-2026-59235
Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts
High
CVE-2026-13164
Unauthenticated self-registration in MailerUp allows access to stored email data
High
CVE-2026-82911
CSRF in Prospero Flow CRM order confirmation allows unauthorized order state changes
Medium
CVE-2026-81931
Unrestricted upload of file with dangerous type in Prospero Flow CRM product photo allows stored cross-site scripting
Medium
CVE-2026-78337
Unrestricted upload of file with dangerous type in Prospero Flow CRM allows stored cross-site scripting via SVG
Medium
CVE-2026-77780
Unvalidated bank account and card foreign keys in the Prospero Flow CRM transaction save endpoint allow cross-tenant disclosure of banking identifiers
Medium
CVE-2026-76203
CSS sanitizer bypass in Pentestify report themes allows forced outbound requests from users' browsers
Medium
CVE-2026-75872
HTML Injection in MailerUp allows attacker-controlled HTML to be delivered in double opt-in verification emails
Medium
CVE-2026-19744
Stored Cross-site Scripting in Pentestify allows JavaScript execution via Markdown links in report fields
Medium
CVE-2026-19716
Stored Cross-site Scripting in Pentestify user account deletion via unescaped username
Medium
CVE-2026-19434
Stored Cross-site Scripting in Pentestify allows JavaScript execution via the finding severity field
Medium
CVE-2026-59232
Stored Cross-site Scripting in Prospero Flow CRM allows JavaScript execution via the lead form name field
Medium
CVE-2026-59231
Server-Side Request Forgery in Pentestify allows authenticated users to trigger outbound server requests via unvalidated image URLs
Medium
CVE-2026-59240
IDOR in Prospero Flow CRM allows deletion of other users notifications
Medium
CVE-2026-59238
Stored XSS in Pentestify via unsanitized finding images and report client logo
Medium
CVE-2026-59237
IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders
Medium
CVE-2026-59236
Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection
Medium
CVE-2026-59234
IDOR in Prospero Flow CRM allows deletion of other users' calendar events
Medium
CVE-2026-13163
Lack of input validation in Mailerup input parameter leads to Open Redirect
Medium
CVE-2026-13150
SSRF in Pentestify PDF generation endpoint via crafted Host header
Medium
Found a vulnerability? Learn more in our Disclosure policy