Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gitea CRITICAL 9.1
CVE-2026-20912

Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea MEDIUM 6.5
CVE-2026-20904

Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20897

Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea CRITICAL 9.1
CVE-2026-20750

Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab…

Fix: 1.25.4+
Fix from $2,300 2026-01-22
Gitea HIGH 7.5
CVE-2026-20736

Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able…

Fix: 1.25.4+
Fix from $1,950 2026-01-22
Gitea MEDIUM 6.5
CVE-2026-20800

Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private r…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Gitea MEDIUM 6.5
CVE-2026-20883

Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still vi…

Fix: 1.25.4+
Fix from $1,600 2026-01-22
Gitea MEDIUM 5.3
CVE-2025-69413

In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

Fix: 1.25.2+
Fix from $1,600 2026-01-01
Gitea MEDIUM 5.4
CVE-2025-68946

In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

Fix: 1.20.1+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68943

Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

Fix: 1.21.8+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68944

Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

Fix: 1.22.2+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68945

In Gitea before 1.21.2, an anonymous user can visit a private user's project.

Fix: 1.21.2+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.4
CVE-2025-68942

Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

Fix: 1.22.2+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68939

Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.

Fix: 1.23.0+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68940

In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.

Fix: 1.22.5+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68941

Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

Fix: 1.22.3+
Fix from $1,600 2025-12-26
Gitea MEDIUM 5.3
CVE-2025-68938

Gitea before 1.25.2 mishandles authorization for deletion of releases.

Fix: 1.25.2+
Fix from $1,600 2025-12-26
Gitea MEDIUM 6.5
CVE-2022-38795

In Gitea through 1.17.1, repo cloning can occur in the migration function.

Fix: after 1.17.1
Fix from $1,600 2023-08-07
Gitea CRITICAL 9.8
CVE-2022-42968

Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

Fix: 1.17.3+
Fix from $2,300 2022-10-16
Gitea MEDIUM 6.5
CVE-2022-38183

In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any i…

Fix: 1.16.9+
Fix from $1,600 2022-08-12
Gitea MEDIUM 5.4
CVE-2022-1928

Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

Fix: 1.16.9+
Fix from $1,600 2022-05-29
Gitea HIGH 7.5
CVE-2022-30781EPSS 89%

Gitea before 1.16.7 does not escape git fetch remote.

Fix: 1.16.7+
Fix from $1,950 2022-05-16
Gitea HIGH 7.5
CVE-2022-27313

An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.

Patch available
Fix from $1,950 2022-05-03
Gitea MEDIUM 6.1
CVE-2022-1058EPSS 53%

Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.

Fix: 1.16.5+
Fix from $1,600 2022-03-24
Gitea MEDIUM 5.3
CVE-2021-29134

The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.

Fix: 1.13.6+
Fix from $1,600 2022-03-15
Gitea HIGH 7.1
CVE-2022-0905

Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.

Fix: 1.16.4+
Fix from $1,950 2022-03-10
Gitea CRITICAL 9.8
CVE-2021-45331

An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for…

Fix: 1.5.0+
Fix from $2,300 2022-02-09
Gitea CRITICAL 9.8
CVE-2021-45330

An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the sessio…

Fix: after 1.15.7
Fix from $2,300 2022-02-09
Gitea MEDIUM 6.1
CVE-2021-45329

Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.

Fix: 1.5.1+
Fix from $1,600 2022-02-08
Gitea MEDIUM 6.1
CVE-2021-45328

Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

Fix: 1.4.3+
Fix from $1,600 2022-02-08