Ctfd maintains a capture-the-flag competition platform designed for security training and event hosting, with a narrow but specialized product footprint centered on its core Ctfd offering and related variants. The durable vulnerability signal centers on authentication and session-management weaknesses, including session fixation and weak password-recovery mechanisms, reflecting the access-control demands of a multi-user competition framework. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ctfd over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-7245CRITICAL Incorrect username validation in the registration process of CTFd v2.0.0 - v2.2.2 allows an attacker to take over an arbitrary account if the username is known and emails are enabl | Jan 23, 2020 | 9.8 | 30 | NO | NO |
CVE-2024-11716MEDIUM While assignment of a user to a team (bracket) in CTFd should be possible only once, at the registration, a flaw in logic implementation allows an authenticated user to reset it's | Jan 2, 2025 | 5.3 | 21 | NO | NO |
CVE-2024-11717MEDIUM Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations. When used, they are sent to the server as a GET parameter and th | Jan 2, 2025 | 6.3 | 19 | NO | NO |
CVE-2020-5290MEDIUM In RedpwnCTF before version 2.3, there is a session fixation vulnerability in exploitable through the `#token=$ssid` hash when making a request to the `/verify` endpoint. An attack | Apr 1, 2020 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ctfd.
Media articles that mention a CVE ID that affects a product developed by Ctfd — matched by CVE ID, not by vendor name.