Flagsmith is a feature-flag management platform with a narrow, focused vulnerability surface centered on its single core product. The observed disclosures reflect the application-layer nature of the service, where the governing weakness characterization remains broad; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Flagsmith over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-52872HIGH In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions. | Nov 17, 2024 | 7.5 | 21 | NO | NO |
CVE-2024-52871HIGH In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting. | Nov 17, 2024 | 7.5 | 19 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Flagsmith.
Media articles that mention a CVE ID that affects a product developed by Flagsmith — matched by CVE ID, not by vendor name.