Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

At0Mxploit

#17387of 53,622
15.5Total CVSS
Vulnerabilities · 2
Medium
1
High
1
PT-2025-39700
8.6
2025-09-27
Flagforge · Flagforge · CVE-2025-59932
**Name of the Vulnerable Software and Affected Versions** Flag Forge versions 2.0.0 through 2.3.0 **Description** The Flag Forge platform contained a security issue where the `/api/resources` API endpoint permitted POST and DELETE requests without appropriate authentication or authorization. This allowed unauthorized users to create, modify, or delete resources. **Recommendations** Upgrade to version 2.3.1 to address the issue.
PT-2025-39658
6.9
2025-09-26
Flagforge · Flagforge · CVE-2025-59843
**Name of the Vulnerable Software and Affected Versions** Flag Forge versions 2.0.0 through 2.3.0 **Description** Flag Forge, a Capture The Flag (CTF) platform, has an issue where the public API endpoint `/api/user/[username]` returns user email addresses in its JSON response. This exposes sensitive user information. The issue is addressed in version 2.3.1, which removes email addresses from public API responses while maintaining the endpoint's public accessibility. The vulnerable parameter is `username`. **Recommendations** Upgrade to Flag Forge version 2.3.1 or later.