{"schema_version":1,"title":"Roskus vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 16 vulnerabilities in Roskus: 0 in the last 7 days and 16 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-82911, was published on 4 September 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/roskus","json_url":"https://junglewise.ai/threats/vendors/roskus.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/roskus","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":16,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":2,"last_90_days":16,"last_365_days":16},"latest":[{"cve":"CVE-2026-82911","cvss":5.1,"epss":0.0023,"slug":"cve-2026-82911-roskus-prospero-flow-crm-cross-site-request-forgery-in-order","title":"Roskus Prospero Flow CRM cross-site request forgery in order confirmation","severity":"info","exploited":false,"published_at":"2026-09-04T16:18:16.313+00:00","url":"https://junglewise.ai/threats/cve-2026-82911-roskus-prospero-flow-crm-cross-site-request-forgery-in-order"},{"cve":"CVE-2026-81931","cvss":4.8,"epss":0.0049,"slug":"cve-2026-81931-roskus-prospero-flow-crm-stored-xss-in-product-photo-upload","title":"Roskus Prospero Flow CRM stored XSS in product photo upload","severity":"info","exploited":false,"published_at":"2026-08-27T20:18:57.2+00:00","url":"https://junglewise.ai/threats/cve-2026-81931-roskus-prospero-flow-crm-stored-xss-in-product-photo-upload"},{"cve":"CVE-2026-78365","epss":0.0051,"slug":"cve-2026-78365-roskus-prospero-flow-crm-authorization-bypass-in-supplier-api","title":"Roskus Prospero Flow CRM authorization bypass in supplier API","severity":"info","exploited":false,"published_at":"2026-08-24T13:19:19.247+00:00","url":"https://junglewise.ai/threats/cve-2026-78365-roskus-prospero-flow-crm-authorization-bypass-in-supplier-api"},{"cve":"CVE-2026-78337","cvss":4.8,"epss":0.004,"slug":"cve-2026-78337-roskus-prospero-flow-crm-stored-xss-in-company-logo-upload","title":"Roskus Prospero Flow CRM stored XSS in company logo upload","severity":"info","exploited":false,"published_at":"2026-08-24T11:16:41.203+00:00","url":"https://junglewise.ai/threats/cve-2026-78337-roskus-prospero-flow-crm-stored-xss-in-company-logo-upload"},{"cve":"CVE-2026-77780","epss":0.0044,"slug":"cve-2026-77780-roskus-prospero-flow-crm-authorization-bypass-in-transaction-save","title":"Roskus Prospero Flow CRM authorization bypass in transaction save","severity":"info","exploited":false,"published_at":"2026-08-21T13:18:20.423+00:00","url":"https://junglewise.ai/threats/cve-2026-77780-roskus-prospero-flow-crm-authorization-bypass-in-transaction-save"},{"cve":"CVE-2026-77759","epss":0.0051,"slug":"cve-2026-77759-roskus-prospero-flow-crm-authorization-bypass-in-transaction-api","title":"Roskus Prospero Flow CRM authorization bypass in transaction API","severity":"info","exploited":false,"published_at":"2026-08-21T12:16:36.533+00:00","url":"https://junglewise.ai/threats/cve-2026-77759-roskus-prospero-flow-crm-authorization-bypass-in-transaction-api"},{"cve":"CVE-2026-19539","cvss":8.3,"epss":0.0044,"slug":"cve-2026-19539-roskus-prospero-flow-crm-authorization-bypass-in-ticket","title":"Roskus Prospero Flow CRM authorization bypass in ticket management","severity":"info","exploited":false,"published_at":"2026-08-11T14:17:13.58+00:00","url":"https://junglewise.ai/threats/cve-2026-19539-roskus-prospero-flow-crm-authorization-bypass-in-ticket"},{"cve":"CVE-2026-19433","cvss":7.1,"epss":0.0044,"slug":"cve-2026-19433-roskus-prospero-flow-crm-authorization-bypass-in-contact","title":"Roskus Prospero Flow CRM authorization bypass in contact management","severity":"info","exploited":false,"published_at":"2026-08-10T15:17:43.33+00:00","url":"https://junglewise.ai/threats/cve-2026-19433-roskus-prospero-flow-crm-authorization-bypass-in-contact"},{"cve":"CVE-2026-59233","cvss":8.8,"epss":0.0041,"slug":"cve-2026-59233-roskus-prospero-flow-crm-missing-authorization-in-permission","title":"Roskus Prospero Flow CRM missing authorization in permission management","severity":"info","exploited":false,"published_at":"2026-08-10T13:19:51.713+00:00","url":"https://junglewise.ai/threats/cve-2026-59233-roskus-prospero-flow-crm-missing-authorization-in-permission"},{"cve":"CVE-2026-59232","cvss":5.3,"slug":"cve-2026-59232-roskus-prospero-flow-crm-stored-xss-in-lead-name-field","title":"Roskus Prospero Flow CRM stored XSS in lead name field","severity":"info","exploited":false,"published_at":"2026-07-31T16:17:08.36+00:00","url":"https://junglewise.ai/threats/cve-2026-59232-roskus-prospero-flow-crm-stored-xss-in-lead-name-field"},{"cve":"CVE-2026-59240","cvss":6.9,"slug":"cve-2026-59240-roskus-prospero-flow-crm-idor-in-deletenotificationcontroller","title":"Roskus Prospero Flow CRM IDOR in DeleteNotificationController","severity":"info","exploited":false,"published_at":"2026-07-27T22:17:54.713+00:00","url":"https://junglewise.ai/threats/cve-2026-59240-roskus-prospero-flow-crm-idor-in-deletenotificationcontroller"},{"cve":"CVE-2026-59239","cvss":8.6,"slug":"cve-2026-59239-roskus-prospero-flow-crm-stored-xss-in-email-module-and-user","title":"Roskus Prospero Flow CRM stored XSS in email module and user signature","severity":"info","exploited":false,"published_at":"2026-07-27T18:16:57.3+00:00","url":"https://junglewise.ai/threats/cve-2026-59239-roskus-prospero-flow-crm-stored-xss-in-email-module-and-user"},{"cve":"CVE-2026-59237","cvss":6.9,"slug":"cve-2026-59237-roskus-prospero-flow-crm-idor-in-order-and-orderitem-api","title":"Roskus Prospero Flow CRM IDOR in Order and OrderItem API","severity":"info","exploited":false,"published_at":"2026-07-16T15:16:34.73+00:00","url":"https://junglewise.ai/threats/cve-2026-59237-roskus-prospero-flow-crm-idor-in-order-and-orderitem-api"},{"cve":"CVE-2026-59236","cvss":6.9,"slug":"cve-2026-59236-roskus-prospero-flow-crm-authorization-bypass-in-excel-import","title":"Roskus Prospero Flow CRM authorization bypass in Excel import","severity":"info","exploited":false,"published_at":"2026-07-15T12:18:17.52+00:00","url":"https://junglewise.ai/threats/cve-2026-59236-roskus-prospero-flow-crm-authorization-bypass-in-excel-import"},{"cve":"CVE-2026-59235","cvss":8.7,"slug":"cve-2026-59235-roskus-prospero-flow-crm-missing-authorization-in","title":"Roskus Prospero Flow CRM missing authorization in BankAccountListController","severity":"info","exploited":false,"published_at":"2026-07-15T11:16:33.493+00:00","url":"https://junglewise.ai/threats/cve-2026-59235-roskus-prospero-flow-crm-missing-authorization-in"},{"cve":"CVE-2026-59234","cvss":6.9,"slug":"cve-2026-59234-roskus-prospero-flow-crm-authorization-bypass-in","title":"Roskus Prospero Flow CRM authorization bypass in CalendarDeleteEventController","severity":"info","exploited":false,"published_at":"2026-07-03T13:17:30.353+00:00","url":"https://junglewise.ai/threats/cve-2026-59234-roskus-prospero-flow-crm-authorization-bypass-in"}],"vendor":{"hub":true,"name":"Roskus","slug":"roskus","homepage":"https://roskus.com/","description":"Roskus is a software developer or entity associated with web application projects.","url":"https://junglewise.ai/threats/vendors/roskus"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":3},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-59233","cvss":8.8,"epss":0.0041,"slug":"cve-2026-59233-roskus-prospero-flow-crm-missing-authorization-in-permission","title":"Roskus Prospero Flow CRM missing authorization in permission management","severity":"info","exploited":false,"published_at":"2026-08-10T13:19:51.713+00:00","url":"https://junglewise.ai/threats/cve-2026-59233-roskus-prospero-flow-crm-missing-authorization-in-permission"},{"cve":"CVE-2026-59235","cvss":8.7,"slug":"cve-2026-59235-roskus-prospero-flow-crm-missing-authorization-in","title":"Roskus Prospero Flow CRM missing authorization in BankAccountListController","severity":"info","exploited":false,"published_at":"2026-07-15T11:16:33.493+00:00","url":"https://junglewise.ai/threats/cve-2026-59235-roskus-prospero-flow-crm-missing-authorization-in"},{"cve":"CVE-2026-59239","cvss":8.6,"slug":"cve-2026-59239-roskus-prospero-flow-crm-stored-xss-in-email-module-and-user","title":"Roskus Prospero Flow CRM stored XSS in email module and user signature","severity":"info","exploited":false,"published_at":"2026-07-27T18:16:57.3+00:00","url":"https://junglewise.ai/threats/cve-2026-59239-roskus-prospero-flow-crm-stored-xss-in-email-module-and-user"},{"cve":"CVE-2026-19539","cvss":8.3,"epss":0.0044,"slug":"cve-2026-19539-roskus-prospero-flow-crm-authorization-bypass-in-ticket","title":"Roskus Prospero Flow CRM authorization bypass in ticket management","severity":"info","exploited":false,"published_at":"2026-08-11T14:17:13.58+00:00","url":"https://junglewise.ai/threats/cve-2026-19539-roskus-prospero-flow-crm-authorization-bypass-in-ticket"},{"cve":"CVE-2026-19433","cvss":7.1,"epss":0.0044,"slug":"cve-2026-19433-roskus-prospero-flow-crm-authorization-bypass-in-contact","title":"Roskus Prospero Flow CRM authorization bypass in contact management","severity":"info","exploited":false,"published_at":"2026-08-10T15:17:43.33+00:00","url":"https://junglewise.ai/threats/cve-2026-19433-roskus-prospero-flow-crm-authorization-bypass-in-contact"},{"cve":"CVE-2026-59240","cvss":6.9,"slug":"cve-2026-59240-roskus-prospero-flow-crm-idor-in-deletenotificationcontroller","title":"Roskus Prospero Flow CRM IDOR in DeleteNotificationController","severity":"info","exploited":false,"published_at":"2026-07-27T22:17:54.713+00:00","url":"https://junglewise.ai/threats/cve-2026-59240-roskus-prospero-flow-crm-idor-in-deletenotificationcontroller"},{"cve":"CVE-2026-59237","cvss":6.9,"slug":"cve-2026-59237-roskus-prospero-flow-crm-idor-in-order-and-orderitem-api","title":"Roskus Prospero Flow CRM IDOR in Order and OrderItem API","severity":"info","exploited":false,"published_at":"2026-07-16T15:16:34.73+00:00","url":"https://junglewise.ai/threats/cve-2026-59237-roskus-prospero-flow-crm-idor-in-order-and-orderitem-api"},{"cve":"CVE-2026-59236","cvss":6.9,"slug":"cve-2026-59236-roskus-prospero-flow-crm-authorization-bypass-in-excel-import","title":"Roskus Prospero Flow CRM authorization bypass in Excel import","severity":"info","exploited":false,"published_at":"2026-07-15T12:18:17.52+00:00","url":"https://junglewise.ai/threats/cve-2026-59236-roskus-prospero-flow-crm-authorization-bypass-in-excel-import"},{"cve":"CVE-2026-59234","cvss":6.9,"slug":"cve-2026-59234-roskus-prospero-flow-crm-authorization-bypass-in","title":"Roskus Prospero Flow CRM authorization bypass in CalendarDeleteEventController","severity":"info","exploited":false,"published_at":"2026-07-03T13:17:30.353+00:00","url":"https://junglewise.ai/threats/cve-2026-59234-roskus-prospero-flow-crm-authorization-bypass-in"},{"cve":"CVE-2026-59232","cvss":5.3,"slug":"cve-2026-59232-roskus-prospero-flow-crm-stored-xss-in-lead-name-field","title":"Roskus Prospero Flow CRM stored XSS in lead name field","severity":"info","exploited":false,"published_at":"2026-07-31T16:17:08.36+00:00","url":"https://junglewise.ai/threats/cve-2026-59232-roskus-prospero-flow-crm-stored-xss-in-lead-name-field"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"Roskus Prospero Flow CRM","slug":"prospero-flow-crm","vulnerabilities":16,"url":"https://junglewise.ai/threats/technologies/prospero-flow-crm"}]}