Vulnerabilities (CVE)

Filtered by vendor Flagsmith Subscribe
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-52871 1 Flagsmith 1 Flagsmith 2025-07-07 N/A 7.5 HIGH
In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.
CVE-2024-52872 1 Flagsmith 1 Flagsmith 2025-07-07 N/A 7.5 HIGH
In Flagsmith before 2.134.1, the get_document endpoint is not correctly protected by permissions.