flagforge has 3 CVEs on record. The median CVSS is 8.6 (high), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.6
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
flagforge vulnerabilities
CVEs affecting flagforge, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2025-61777Critical· 9.4PoCFlag Forge is a Capture The Flag (CTF) platform
Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create` (POST) endpoints previously allowed access without auth…
CVE-2025-59932High· 8.6Flag Forge is a Capture The Flag (CTF) platform
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authentication or authorization. This could have enabled unautho…
CVE-2025-59843Medium· 5.3PoCFlag Forge is a Capture The Flag (CTF) platform
Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. The fix, intended for release in 2.3.1 but only available s…