Known Vulnerabilities for Flow by Nextcloud
Listed below are 1 of the newest known vulnerabilities associated with "Flow" by "Nextcloud".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77780 json | Authorization Bypass Through User-Controlled Key in the transaction save endpoint in Roskus Prospero Flow CRM 4.9.1 through 5... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77759 json | Authorization Bypass Through User-Controlled Key in the transaction API in Roskus Prospero Flow CRM 5.0.0 through 5.3.5 allow... | Not Provided | 2026-08-21 | 2026-08-21 |
| CVE-2026-77069 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-to-acc... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-76633 json | WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated u... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-76319 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a low-privileged user that does not hold the fsh_mana... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76311 json | In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, an unauthenticated user who has an embedded report to... | Not Provided | 2026-08-19 | 2026-08-21 |
| CVE-2026-76242 json | stigmem-node 0.9.0a1 accepts federation peer key material during peer registration without a separate administrator out-of-ba... | Not Provided | 2026-08-19 | 2026-08-20 |
| CVE-2026-75833 json | The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav 2.0's admin-next/API stack) before version 1.0.14 contains an... | Not Provided | 2026-08-18 | 2026-08-18 |
| CVE-2026-75628 json | Punk::OAuth2 versions before 0.03 for Perl allow an attacker-chosen off-site redirect after login because same_origin_path ac... | Not Provided | 2026-08-20 | 2026-08-20 |
| CVE-2026-75583 json | keeper.sh's calendar module version prior to 2.18.14 contains a server-side request forgery (SSRF) guard bypass vulnerability... | Not Provided | 2026-08-19 | 2026-08-19 |