Vulnerability index

Browse CVEs

47 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Gogs MEDIUM 5.4
CVE-2026-26276

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone…

Fix: 0.14.2+
Fix from $1,600 2026-03-05
Gogs MEDIUM 5.3
CVE-2026-26196

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params like token and access_token, whi…

Fix: 0.14.2+
Fix from $1,600 2026-03-05
Gogs CRITICAL 9.3
CVE-2026-25921

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack,…

Fix: 0.14.2+
Fix from $2,300 2026-03-05
Gogs HIGH 7.3
CVE-2026-26194

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user…

Fix: 0.14.2+
Fix from $1,950 2026-03-05
Gogs MEDIUM 6.1
CVE-2026-26195

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe template rendering that mixes us…

Fix: 0.14.2+
Fix from $1,600 2026-03-05
Gogs MEDIUM 5.4
CVE-2026-26022

Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and …

Fix: 0.14.2+
Fix from $1,600 2026-03-05
Gogs CRITICAL 9.8
CVE-2026-25242

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global Re…

Fix: 0.14.1+
Fix from $2,300 2026-02-19
Gogs HIGH 8.8
CVE-2026-25232

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository col…

Fix: 0.14.1+
Fix from $1,950 2026-02-19
Gogs MEDIUM 6.5
CVE-2026-25229

Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability which allows authenticated users…

Fix: 0.14.1+
Fix from $1,600 2026-02-19
Gogs HIGH 8.1
CVE-2026-24135

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of …

Fix: 0.13.4+
Fix from $1,950 2026-02-06
Gogs MEDIUM 6.5
CVE-2026-22592

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files i…

Fix: 0.13.4+
Fix from $1,600 2026-02-06
Gogs MEDIUM 6.5
CVE-2026-23632

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/contents/*" does not require write…

Fix: 0.13.4+
Fix from $1,600 2026-02-06
Gogs MEDIUM 6.5
CVE-2026-23633

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via path traversal in Git hook edi…

Fix: 0.13.4+
Fix from $1,600 2026-02-06
Gogs HIGH 8.8
CVE-2025-64175

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enablin…

Fix: 0.13.4+
Fix from $1,950 2026-02-06
Gogs CRITICAL 9.8
CVE-2025-64111

Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to…

Fix: 0.13.4+
Fix from $2,300 2026-02-06
Gogs HIGH 8.8
CVE-2025-8110 KEVEPSS 83%

Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.

Fix: after 0.13.3
Fix from $1,950 2025-12-10
Gogs CRITICAL 9.8
CVE-2024-56731

Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve rem…

Fix: 0.13.3+
Fix from $2,300 2025-06-24
Gogs CRITICAL 9.8
CVE-2024-54148

Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access…

Fix: 0.13.1+
Fix from $2,300 2024-12-23
Gogs HIGH 8.8
CVE-2024-55947EPSS 75%

Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the…

Fix: 0.13.1+
Fix from $1,950 2024-12-23
Gogs HIGH 8.8
CVE-2024-44625EPSS 15%

Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

Fix: after 0.13.0
Fix from $1,950 2024-11-15
Gogs CRITICAL 9.8
CVE-2022-1884

A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to imp…

Fix: after 0.12.7
Fix from $2,300 2024-11-15
Gogs CRITICAL 9.9
CVE-2024-39930EPSS 8%

The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated atta…

Fix: after 0.13.0
Fix from $2,300 2024-07-04
Gogs CRITICAL 9.9
CVE-2024-39931EPSS 53%

Gogs through 0.13.0 allows deletion of internal files.

Fix: after 0.13.0
Fix from $2,300 2024-07-04
Gogs CRITICAL 9.9
CVE-2024-39932EPSS 17%

Gogs through 0.13.0 allows argument injection during the previewing of changes.

Fix: after 0.13.0
Fix from $2,300 2024-07-04
Gogs HIGH 7.7
CVE-2024-39933

Gogs through 0.13.0 allows argument injection during the tagging of a new release.

Fix: after 0.13.0
Fix from $1,950 2024-07-04
Gogs CRITICAL 9.8
CVE-2022-2024EPSS 98%

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.

Fix: 0.12.11+
Fix from $2,300 2023-02-25
Gogs CRITICAL 9.0
CVE-2022-32174EPSS 58%

In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

Fix: after 0.12.10
Fix from $2,300 2022-10-11
Gogs MEDIUM 5.4
CVE-2022-31038

Gogs is an open source self-hosted Git service. In versions of gogs prior to 0.12.9 `DisplayName` does not filter characters input from users, which …

Fix: 0.12.9+
Fix from $1,600 2022-06-09
Gogs CRITICAL 9.8
CVE-2022-1986

OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.

Fix: 0.12.9+
Fix from $2,300 2022-06-09
Gogs CRITICAL 9.1
CVE-2022-1992

Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.

Fix: 0.12.9+
Fix from $2,300 2022-06-09