📦 Flagforge

by Flagforge

🔍 What is Flagforge?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-61777

CRITICAL CVSS 9.4 Oct 6, 2025

Flag Forge CTF platform versions 2.0.0 through 2.3.1 have unauthenticated API endpoints that allow unauthorized users to view all badge templates with sensitive metadata and create arbitrary badge tem...

CVE-2025-59841

CRITICAL CVSS 9.8 Sep 25, 2025

Flag Forge CTF platform versions 2.2.0 through 2.3.0 have a session invalidation vulnerability where authenticated users can continue accessing protected endpoints and CSRF tokens remain valid after l...

CVE-2025-59932

HIGH CVSS 8.6 Sep 27, 2025

This vulnerability in Flag Forge CTF platform allows unauthenticated attackers to create, modify, or delete platform resources via the /api/resources endpoint. It affects all deployments running versi...

CVE-2025-59826

HIGH CVSS 7.6 Sep 23, 2025

In Flag Forge CTF platform version 2.1.0, non-admin users can create arbitrary challenges, allowing them to introduce malicious, incorrect, or misleading content. This affects all deployments running ...

CVE-2025-59843

MEDIUM CVSS 5.3 Sep 26, 2025

Flag Forge CTF platform versions 2.0.0 through 2.3.1 expose user email addresses through a public API endpoint. This vulnerability allows unauthenticated attackers to harvest email addresses of regist...