VYPR
Vendor

Roskus

Products
1
CVEs
19
Across products
19
Status
Private

Products

1

Recent CVEs

19
  • CVE-2026-59239HigJul 27, 2026
    risk 0.56cvss epss 0.00

    Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account…

  • CVE-2026-78365CriAug 24, 2026
    risk 0.53cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 allows any authenticated user to read and modify another company's supplier record, and to reassign it to their own company, via a PUT request to…

  • CVE-2026-19871CriAug 14, 2026
    risk 0.53cvss epss 0.00

    Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save…

  • CVE-2026-77759HigAug 21, 2026
    risk 0.50cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allows an authenticated user to read the transactions of other companies on the same instance via an incremented identifier in GET /api/transaction/{id}, which…

  • CVE-2026-59233HigAug 10, 2026
    risk 0.50cvss epss 0.00

    Missing Authorization in the permission management component in Roskus Prospero Flow CRM before 5.2.1 allows any authenticated user to grant any role, including their own, the complete set of application permissions via a crafted POST request to the permission save endpoint,…

  • CVE-2026-19870HigAug 14, 2026
    risk 0.49cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users…

  • CVE-2026-19734HigAug 13, 2026
    risk 0.49cvss epss 0.00

    Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another…

  • CVE-2026-19539HigAug 11, 2026
    risk 0.49cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to…

  • CVE-2026-19433HigAug 10, 2026
    risk 0.49cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the contact management component in Roskus Prospero Flow CRM before 5.4.8 allows authenticated users of any company to blindly overwrite the contact data of another company and to download that contact's personal data as a…

  • CVE-2026-59240MedJul 27, 2026
    risk 0.45cvss epss 0.00

    The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authenticated user, regardless of company or permissions, to delete notifications…

  • CVE-2026-77780MedAug 21, 2026
    risk 0.27cvss epss 0.00

    Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5.14.0 allows a user with transaction and accounting creation permissions to disclose another company's bank account name, bank name and card last four…

  • CVE-2026-59232MedJul 31, 2026
    risk 0.27cvss epss 0.00

    Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view…

  • CVE-2026-82911MedSep 4, 2026
    risk 0.26cvss epss 0.00

    Cross-Site Request Forgery (CSRF) in the OrderConfirmController at GET /order/confirm/{order_number} in Roskus Prospero Flow CRM before 5.15.11 allows an unauthenticated attacker to confirm any order on behalf of an authenticated user by directing them to a crafted page.…

  • CVE-2026-81931MedAug 27, 2026
    risk 0.24cvss epss 0.00

    Unrestricted Upload of File with Dangerous Type in the product photo upload in Roskus Prospero Flow CRM before 5.16.0 allows an authenticated user holding the create product permission (routine Seller role) to execute arbitrary JavaScript in the application origin. The photo…

  • CVE-2026-78337MedAug 24, 2026
    risk 0.24cvss epss 0.00

    Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 allows an authenticated user holding the create company and update company permissions to execute arbitrary JavaScript in the application origin via an SVG…

  • CVE-2026-59237MedJul 16, 2026
    risk 0.00cvss epss 0.01

    Authorization Bypass Through User-Controlled Key (CWE-639) in the Order and OrderItem REST API controllers in Roskus Prospero Flow CRM before 5.5.3 allows a remote, authenticated user to read, modify, and delete orders and order items belonging to any other company (tenant) via…

  • CVE-2026-59236MedJul 15, 2026
    risk 0.00cvss epss 0.01

    Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, ProductImport) in Roskus Prospero Flow CRM before 5.14.0 allows a remote, authenticated user of any role or company to create customer, lead, and product records…

  • CVE-2026-59235HigJul 15, 2026
    risk 0.00cvss epss 0.01

    Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListController.php), exposed at GET /api/bank-account, in Prospero Flow CRM <5.5.3, which allows a remote, authenticated attacker holding a low-privileged role (e.g. the…

  • CVE-2026-59234MedJul 3, 2026
    risk 0.00cvss epss 0.01

    Authorization Bypass Through User-Controlled Key (CWE-639) in CalendarDeleteEventController (app/Http/Controllers/Calendar/CalendarDeleteEventController.php), exposed at GET /calendar/event/delete/{id}, in Prospero Flow CRM before 5.5.3 allows a remote, authenticated attacker to…