PatchSiren debrief for CVE-2026-77759 based on the supplied source corpus. The CVE record was published on 2026-08-21T12:16:36.533Z and has not been modified since then. This vulnerability exists in Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5, allowing an authenticated user to read transactions of other companies by incrementing the identifier in the GET /api/transaction/{id} request. The API re [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-31T16:17:08.360Z and has not been modified since then. The vulnerability is a cross-site scripting issue in Roskus Prospero Flow CRM before version 5.3.7, allowing authenticated users with create or update lead permissions to execute arbitrary JavaScript. This could lead to security breaches if expl [truncated]
CVE-2026-59239 is a Stored Cross-site Scripting (CWE-79) vulnerability in the email module of Roskus Prospero Flow CRM before version 5.4.4. This vulnerability allows a remote, authenticated low-privileged user to execute arbitrary JavaScript in another user's browser, including administrators, leading to session compromise and account takeover. The vulnerability is exploited via a payload stored in an em [truncated]
CVE-2026-59237 is an authorization bypass vulnerability in Roskus Prospero Flow CRM before 5.5.3. A remote, authenticated user can read, modify, and delete orders and order items belonging to any other company (tenant) via a sequential numeric {id} supplied to GET /api/order/{id}, PUT /api/order/{id}, GET /api/order-item/{id}, PUT /api/order-item/{id}, or DELETE /api/order-item/{id}. The vulnerability exi [truncated]