Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-19871: CWE-798 Use of Hard-coded Credentials in Roskus Prospero Flow CRMCVE-2026-19871
0

Use of Hard-coded Credentials in the human resources component in Roskus Prospero Flow CRM before 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow, knowing only their email address, because the employee save controller falls back to the literal password "changeme" and the onboarding form provides no password field.

Join the discussion
CVE-2026-19870: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRMCVE-2026-19870
0

Authorization Bypass Through User-Controlled Key in the payroll module in Roskus Prospero Flow CRM before 5.15.10 allows authenticated users holding the read payroll permission to view the salary and banking details of employees of any other company in the instance, and users holding the create payroll permission to create payroll records attributed to another company's employees, because the listing query is not scoped to the caller's company and the employee identifier is validated for global existence rather than company membership

Join the discussion
CVE-2026-19734: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRMCVE-2026-19734
0

Missing Authorization and Authorization Bypass Through User-Controlled Key in the product management component in Roskus Prospero Flow CRM before 5.4.7 allows authenticated users of any company to read the full sensitive data (price, cost, stock, SKU, and barcode) of another company's product and to hijack that product by reassigning its company_id, via the product's numeric identifier, because `ProductUpdateController` did not extend `MainController` and therefore required no authentication check on the read endpoint, and `ProductRepository::save()` retrieved the record via `Product::find($data['id'])` without constraining the query to the authenticated user's company before overwriting its company_id.

Join the discussion
CVE-2026-19539: CWE-862 Missing Authorization in Roskus Prospero Flow CRMCVE-2026-19539
0

Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission.

Join the discussion
CVE-2026-19433: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRMCVE-2026-19433
0

CVE-2026-19433 is an authorization bypass vulnerability in Roskus Prospero Flow CRM before version 5.4.8. It affects the contact management component, allowing authenticated users from any company to overwrite contact data of other companies and download personal contact data as vCards. This occurs because save and export operations do not restrict queries to the authenticated user's company.

Join the discussion
CVE-2026-59233: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRMCVE-2026-59233
0

CVE-2026-59233 is a high-severity authorization bypass vulnerability in Roskus Prospero Flow CRM versions prior to 5.2.1. The flaw exists in the permission management component, where the permission save endpoint does not perform authorization checks. This allows any authenticated user to grant any role, including their own, full application permissions by sending a crafted POST request.

Join the discussion
CVE-2026-59232: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in Roskus Prospero Flow CRMCVE-2026-59232
0

Cross-site Scripting in the lead index view in Roskus Prospero Flow CRM before 5.3.7 allows authenticated users holding the create or update lead permission to execute arbitrary JavaScript in the application origin via HTML markup stored in the lead name field, which the view renders through Blade's unescaped output directive and inside a JavaScript string literal in an onclick attribute.

Join the discussion
CVE-2026-59240: CWE-639 Authorization bypass through User-Controlled key in Roskus Prospero Flow CRMCVE-2026-59240
0

The vulnerability involves an Insecure Direct Object Reference (IDOR) in the `DeleteNotificationController::delete()` method at endpoint `GET /notification/delete/{id}`. The flaw allows any authenticated user, regardless of company or permissions, to delete notifications belonging to any other user in the system. The controller retrieves the target record with `Notification::findOrFail($id)` and deletes it without validating `user_id` or `company_id` ownership, unlike the sibling `SetNotificationReadAjaxController`, which correctly scopes lookups by `Auth::id()`. Because notification identifiers are sequential, an attacker can iterate over IDs to systematically delete notifications belonging to any user, denying them visibility of ticket alerts, task assignments, and other system events.

Join the discussion
CVE-2026-59239: CWE-79 Improper neutralization of input during web page generation ('cross-site scripting') in Roskus Prospero Flow CRMCVE-2026-59239
0

Stored Cross-site Scripting (CWE-79) in the email module in Roskus Prospero Flow CRM before 5.4.4 allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover, via a payload stored in an email body that is persisted without sanitization and rendered unescaped with {!! $email->body !!} when the recipient opens the message.

Join the discussion

Showing 1 to 9 of 9 results

Filters:Package: pkg:github/Prospero Flow CRM
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses