Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2026-26276 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone… Gogs 0.14.2+ Fix from $1,6002026-03-05 MEDIUM 5.3 CVE-2026-26196 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, whi… Gogs 0.14.2+ Fix from $1,6002026-03-05 CRITICAL 9.3 CVE-2026-25921 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack,… Gogs 0.14.2+ Fix from $2,3002026-03-05 HIGH 7.3 CVE-2026-26194 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user… Gogs 0.14.2+ Fix from $1,9502026-03-05 MEDIUM 6.1 CVE-2026-26195 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe template rendering that mixes us… Gogs 0.14.2+ Fix from $1,6002026-03-05 MEDIUM 5.4 CVE-2026-26022 Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and … Gogs 0.14.2+ Fix from $1,6002026-03-05 CRITICAL 9.8 CVE-2026-25242 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global Re… Gogs 0.14.1+ Fix from $2,3002026-02-19 HIGH 8.8 CVE-2026-25232 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository col… Gogs 0.14.1+ Fix from $1,9502026-02-19 MEDIUM 6.5 CVE-2026-25229 Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users… Gogs 0.14.1+ Fix from $1,6002026-02-19 HIGH 8.1 CVE-2026-24135 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of … Gogs 0.13.4+ Fix from $1,9502026-02-06 MEDIUM 6.5 CVE-2026-22592 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files i… Gogs 0.13.4+ Fix from $1,6002026-02-06 MEDIUM 6.5 CVE-2026-23632 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write… Gogs 0.13.4+ Fix from $1,6002026-02-06 MEDIUM 6.5 CVE-2026-23633 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook edi… Gogs 0.13.4+ Fix from $1,6002026-02-06 HIGH 8.8 CVE-2025-64175 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enablin… Gogs 0.13.4+ Fix from $1,9502026-02-06 CRITICAL 9.8 CVE-2025-64111 Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to… Gogs 0.13.4+ Fix from $2,3002026-02-06 HIGH 8.8 CVE-2025-8110 KEVEPSS 83% Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. Gogs after 0.13.3 Fix from $1,9502025-12-10 CRITICAL 9.8 CVE-2024-56731 Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve rem… Gogs 0.13.3+ Fix from $2,3002025-06-24 CRITICAL 9.8 CVE-2024-54148 Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access… Gogs 0.13.1+ Fix from $2,3002024-12-23 HIGH 8.8 CVE-2024-55947EPSS 75% Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the… Gogs 0.13.1+ Fix from $1,9502024-12-23 HIGH 8.8 CVE-2024-44625EPSS 15% Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go. Gogs after 0.13.0 Fix from $1,9502024-11-15 CRITICAL 9.8 CVE-2022-1884 A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp… Gogs after 0.12.7 Fix from $2,3002024-11-15 CRITICAL 9.9 CVE-2024-39930EPSS 8% The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated atta… Gogs after 0.13.0 Fix from $2,3002024-07-04 CRITICAL 9.9 CVE-2024-39931EPSS 53% Gogs through 0.13.0 allows deletion of internal files. Gogs after 0.13.0 Fix from $2,3002024-07-04 CRITICAL 9.9 CVE-2024-39932EPSS 17% Gogs through 0.13.0 allows argument injection during the previewing of changes. Gogs after 0.13.0 Fix from $2,3002024-07-04 HIGH 7.7 CVE-2024-39933 Gogs through 0.13.0 allows argument injection during the tagging of a new release. Gogs after 0.13.0 Fix from $1,9502024-07-04 CRITICAL 9.8 CVE-2022-2024EPSS 98% OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. Gogs 0.12.11+ Fix from $2,3002023-02-25 CRITICAL 9.0 CVE-2022-32174EPSS 58% In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. Gogs after 0.12.10 Fix from $2,3002022-10-11 MEDIUM 5.4 CVE-2022-31038 Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which … Gogs 0.12.9+ Fix from $1,6002022-06-09 CRITICAL 9.8 CVE-2022-1986 OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. Gogs 0.12.9+ Fix from $2,3002022-06-09 CRITICAL 9.1 CVE-2022-1992 Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. Gogs 0.12.9+ Fix from $2,3002022-06-09