Flagforge operates a narrowly scoped product line that has generated a disproportionate share of serious-severity vulnerabilities, with critical flaws skewing toward authentication and information-disclosure boundaries. The recurring weakness classes—improper access control, missing authorization, exposure of sensitive information, and inefficient regular expression complexity—reflect gaps in the permission and parsing layer that are characteristic of systems handling user data or multi-tenant isolation. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flagforge over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-59841CRITICAL Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.2.0 to before 2.3.1, the FlagForge web application improperly handles session invalidation. Authenticated users | Sep 25, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-59827CRITICAL Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, the /api/admin/assign-badge endpoint lacks proper access control, allowing any authenticated user to assign high- | Sep 24, 2025 | 9.8 | 30 | NO | NO |
CVE-2025-61777CRITICAL Flag Forge is a Capture The Flag (CTF) platform. Starting in version 2.0.0 and prior to version 2.3.2, the `/api/admin/badge-templates` (GET) and `/api/admin/badge-templates/create | Oct 6, 2025 | 9.1 | 29 | NO | NO |
CVE-2025-59932HIGH Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.1, the /api/resources endpoint previously allowed POST and DELETE requests without proper authent | Sep 27, 2025 | 8.2 | 28 | NO | NO |
CVE-2026-21868HIGH Flag Forge is a Capture The Flag (CTF) platform. Versions 2.3.2 and below have a Regular Expression Denial of Service (ReDoS) vulnerability in the user profile API endpoint (/api/u | Jan 8, 2026 | 7.5 | 25 | NO | NO |
CVE-2025-59833HIGH Flag Forge is a Capture The Flag (CTF) platform. In versions from 2.1.0 to before 2.3.0, the API endpoint GET /api/problems/:id returns challenge hints in plaintext within the ques | Sep 24, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-59826HIGH Flag Forge is a Capture The Flag (CTF) platform. In version 2.1.0, non-admin users can create arbitrary challenges, potentially introducing malicious, incorrect, or misleading cont | Sep 23, 2025 | 7.6 | 25 | NO | NO |
CVE-2025-59843MEDIUM Flag Forge is a Capture The Flag (CTF) platform. From versions 2.0.0 to before 2.3.2, the public endpoint /api/user/[username] returns user email addresses in its JSON response. Th | Sep 26, 2025 | 5.3 | 21 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flagforge.
Media articles that mention a CVE ID that affects a product developed by Flagforge — matched by CVE ID, not by vendor name.