Vulnerabilities published by Secur0
Explore the list of CVEs reported through Secur0's programs. Check technical details and vulnerability statuses.
CVE-2026-59239
Stored XSS in Prospero Flow CRM email body allows administrator account takeover
High
CVE-2026-59235
Missing authorization in Prospero Flow CRM allows low-privileged users to read all bank accounts
High
CVE-2026-13164
Unauthenticated self-registration in MailerUp allows access to stored email data
High
CVE-2026-59232
Stored Cross-site Scripting in Prospero Flow CRM allows JavaScript execution via the lead form name field
Medium
CVE-2026-59231
Server-Side Request Forgery in Pentestify allows authenticated users to trigger outbound server requests via unvalidated image URLs
Medium
CVE-2026-59240
IDOR in Prospero Flow CRM allows deletion of other users notifications
Medium
CVE-2026-59238
Stored XSS in Pentestify via unsanitized finding images and report client logo
Medium
CVE-2026-59237
IDOR in Prospero Flow CRM Order API allows cross-tenant read and modification of orders
Medium
CVE-2026-59236
Authorization bypass in Prospero Flow CRM Excel import allows cross-tenant record injection
Medium
CVE-2026-59234
IDOR in Prospero Flow CRM allows deletion of other users' calendar events
Medium
CVE-2026-13163
Lack of input validation in Mailerup input parameter leads to Open Redirect
Medium
CVE-2026-13150
SSRF in Pentestify PDF generation endpoint via crafted Host header
Medium
Found a vulnerability? Learn more in our Disclosure policy