CVE-2025-59932High· 8.6▾ TwilightFlag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unautho…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 47.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unauthorized users to create, modify, or delete resources on the platform. The issue has been fixed in FlagForge version 2.3.1.
flagforge >= 2.0, < 2.3.1Upgrade past the affected range:
flagforge 2.3.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61777Critical· 9.4Flag Forge is a Capture The Flag (CTF) platform
CVE-2025-59843Medium· 5.3Flag Forge is a Capture The Flag (CTF) platform
CVE-2025-11352Medium· 6.3A security vulnerability has been detected in code-projects Online Hotel Reservation System 1.0
CVE-2025-11351Medium· 6.3A weakness has been identified in code-projects Online Hotel Reservation System 1.0
CVE-2025-11347High· 7.3A vulnerability was found in code-projects Student Crud Operation up to 3.3
CVE-2025-11320Medium· 6.3A security vulnerability has been detected in zhuimengshaonian wisdom-education up to 1.0.4