CVE-2025-59843Medium· 5.3▾ TwilightPoC availableFlag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available s…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 29.2 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
1 GitHub repo (last check)
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available starting in version 2.3.2, removes email addresses from public API responses while keeping the endpoint publicly accessible. Users should upgrade to version 2.3.2 or later to eliminate exposure. There are no workarounds for this vulnerability.
flagforge >= 2.0, < 2.3.1Upgrade past the affected range:
flagforge 2.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61777Critical· 9.4Flag Forge is a Capture The Flag (CTF) platform
CVE-2025-59932High· 8.6Flag Forge is a Capture The Flag (CTF) platform
CVE-2025-12536Medium· 5.3The SureForms plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.13.1 via the '_srfm_email_notification' post meta registration
CVE-2020-37173High· 7.5AVideo Platform 8.1 - Information Disclosure (User Enumeration)
CVE-2026-39372Medium· 4.9InvoicePlane is a self-hosted open source application for managing invoices, clients, and payments
CVE-2026-53497Medium· 5.3CrossWatch (CW) is a synchronization engine