Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
CRITICAL 9.1
CVE-2026-20912
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could pote…
Gitea
1.25.4+
MEDIUM 6.5
CVE-2026-20904
Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings o…
Gitea
1.25.4+
CRITICAL 9.1
CVE-2026-20897
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete L…
Gitea
1.25.4+
CRITICAL 9.1
CVE-2026-20750
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be ab…
Gitea
1.25.4+
HIGH 7.5
CVE-2026-20736
Gitea does not properly verify repository context when deleting attachments. A user who previously uploaded an attachment to a repository may be able…
Gitea
1.25.4+
MEDIUM 6.5
CVE-2026-20800
Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private r…
Gitea
1.25.4+
MEDIUM 6.5
CVE-2026-20883
Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still vi…
Gitea
1.25.4+
MEDIUM 5.3
CVE-2025-69413
In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.
Gitea
1.25.2+
MEDIUM 5.4
CVE-2025-68946
In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
Gitea
1.20.1+
MEDIUM 5.3
CVE-2025-68943
Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.
Gitea
1.21.8+
MEDIUM 5.3
CVE-2025-68944
Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.
Gitea
1.22.2+
MEDIUM 5.3
CVE-2025-68945
In Gitea before 1.21.2, an anonymous user can visit a private user's project.
Gitea
1.21.2+
MEDIUM 5.4
CVE-2025-68942
Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.
Gitea
1.22.2+
MEDIUM 5.3
CVE-2025-68939
Gitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.
Gitea
1.23.0+
MEDIUM 5.3
CVE-2025-68940
In Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.
Gitea
1.22.5+
MEDIUM 5.3
CVE-2025-68941
Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.
Gitea
1.22.3+
MEDIUM 5.3
CVE-2025-68938
Gitea before 1.25.2 mishandles authorization for deletion of releases.
Gitea
1.25.2+
MEDIUM 6.5
CVE-2022-38795
In Gitea through 1.17.1, repo cloning can occur in the migration function.
Gitea
after 1.17.1
CRITICAL 9.8
CVE-2022-42968
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
Gitea
1.17.3+
MEDIUM 6.5
CVE-2022-38183
In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any i…
Gitea
1.16.9+
MEDIUM 5.4
CVE-2022-1928
Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.
Gitea
1.16.9+
HIGH 7.5
CVE-2022-30781EPSS 89%
Gitea before 1.16.7 does not escape git fetch remote.
Gitea
1.16.7+
HIGH 7.5
CVE-2022-27313
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration file.
Gitea
Patch available
MEDIUM 6.1
CVE-2022-1058EPSS 53%
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
Gitea
1.16.5+
MEDIUM 5.3
CVE-2021-29134
The avatar middleware in Gitea before 1.13.6 allows Directory Traversal via a crafted URL.
Gitea
1.13.6+
HIGH 7.1
CVE-2022-0905
Missing Authorization in GitHub repository go-gitea/gitea prior to 1.16.4.
Gitea
1.16.4+
CRITICAL 9.8
CVE-2021-45331
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for…
Gitea
1.5.0+
CRITICAL 9.8
CVE-2021-45330
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the sessio…
Gitea
after 1.15.7
MEDIUM 6.1
CVE-2021-45329
Cross Site Scripting (XSS) vulnerability exists in Gitea before 1.5.1 via the repository settings inside the external wiki/issue tracker URL field.
Gitea
1.5.1+
MEDIUM 6.1
CVE-2021-45328
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
Gitea
1.4.3+