CVE-2024-52871: Flagsmith
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
In Flagsmith before 2.134.1, it is possible to bypass the ALLOW_REGISTRATION_WITHOUT_INVITE setting.
Affected products
- Flagsmith Flagsmith: before 2.134.1 (fixed in 2.134.1)
Published 2024-11-17. Last modified 2026-06-17.