Vulnerability index

Browse CVEs

48 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-20912 Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote… Gitea 1.25.4+ Fix from $2,3002026-01-22 MEDIUM 6.5 CVE-2026-20904 Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o… Gitea 1.25.4+ Fix from $1,6002026-01-22 CRITICAL 9.1 CVE-2026-20897 Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L… Gitea 1.25.4+ Fix from $2,3002026-01-22 CRITICAL 9.1 CVE-2026-20750 Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab… Gitea 1.25.4+ Fix from $2,3002026-01-22 HIGH 7.5 CVE-2026-20736 Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able… Gitea 1.25.4+ Fix from $1,9502026-01-22 MEDIUM 6.5 CVE-2026-20800 Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private r… Gitea 1.25.4+ Fix from $1,6002026-01-22 MEDIUM 6.5 CVE-2026-20883 Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still vi… Gitea 1.25.4+ Fix from $1,6002026-01-22 MEDIUM 5.3 CVE-2025-69413 In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists. Gitea 1.25.2+ Fix from $1,6002026-01-01 MEDIUM 5.4 CVE-2025-68946 In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. Gitea 1.20.1+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68943 Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order. Gitea 1.21.8+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68944 Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries. Gitea 1.22.2+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68945 In Gitea before 1.21.2, an anonymous user can visit a private user's project. Gitea 1.21.2+ Fix from $1,6002025-12-26 MEDIUM 5.4 CVE-2025-68942 Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text. Gitea 1.22.2+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68939 Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API. Gitea 1.23.0+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68940 In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request. Gitea 1.22.5+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68941 Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources. Gitea 1.22.3+ Fix from $1,6002025-12-26 MEDIUM 5.3 CVE-2025-68938 Gitea before 1.25.2 mishandles authorization for deletion of releases. Gitea 1.25.2+ Fix from $1,6002025-12-26 MEDIUM 6.5 CVE-2022-38795 In Gitea through 1.17.1, repo cloning can occur in the migration function. Gitea after 1.17.1 Fix from $1,6002023-08-07 CRITICAL 9.8 CVE-2022-42968 Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled. Gitea 1.17.3+ Fix from $2,3002022-10-16 MEDIUM 6.5 CVE-2022-38183 In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any i… Gitea 1.16.9+ Fix from $1,6002022-08-12 MEDIUM 5.4 CVE-2022-1928 Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9. Gitea 1.16.9+ Fix from $1,6002022-05-29 HIGH 7.5 CVE-2022-30781EPSS 89% Gitea before 1.16.7 does not escape git fetch remote. Gitea 1.16.7+ Fix from $1,9502022-05-16 HIGH 7.5 CVE-2022-27313 An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file. Gitea Patch available Fix from $1,9502022-05-03 MEDIUM 6.1 CVE-2022-1058EPSS 53% Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5. Gitea 1.16.5+ Fix from $1,6002022-03-24 MEDIUM 5.3 CVE-2021-29134 The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL. Gitea 1.13.6+ Fix from $1,6002022-03-15 HIGH 7.1 CVE-2022-0905 Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4. Gitea 1.16.4+ Fix from $1,9502022-03-10 CRITICAL 9.8 CVE-2021-45331 An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for… Gitea 1.5.0+ Fix from $2,3002022-02-09 CRITICAL 9.8 CVE-2021-45330 An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the sessio… Gitea after 1.15.7 Fix from $2,3002022-02-09 MEDIUM 6.1 CVE-2021-45329 Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field. Gitea 1.5.1+ Fix from $1,6002022-02-08 MEDIUM 6.1 CVE-2021-45328 Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs. Gitea 1.4.3+ Fix from $1,6002022-02-08