Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gogs gogs vulnerabilities and exploits
(subscribe to this query)
755
VMScore
CVE-2014-8681
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.6.x prior to 0.5.6.1025 Beta allows remote malicious users to execute arbitrary SQL commands via the label parameter to user/repos/issues.
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
Gogits Gogs 0.3.1-9
1 EDB exploit
755
VMScore
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.6.1105 Beta allow remote malicious users to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/re...
Gogits Gogs 0.3.1-9
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
1 EDB exploit
383
VMScore
CVE-2014-8683
Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.8 allows remote malicious users to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.
Gogits Gogs 0.3.1-9
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
383
VMScore
CVE-2020-9329
Gogs up to and including 0.11.91 allows malicious users to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Gogs Gogs
516
VMScore
CVE-2018-15178
Open redirect vulnerability in Gogs prior to 0.12 allows remote malicious users to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go...
Gogs Gogs
446
VMScore
CVE-2022-0870
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.5.
Gogs Gogs
578
VMScore
CVE-2020-15867
The git hook feature in Gogs 0.5.5 up to and including 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in th...
Gogs Gogs
383
VMScore
CVE-2022-1285
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.8.
Gogs Gogs
312
VMScore
CVE-2022-1464
Stored xss bug in GitHub repository gogs/gogs before 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .
Gogs Gogs
668
VMScore
CVE-2022-1986
OS Command Injection in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-27322
administrator privileges
CVE-2024-1579
hardcoded
CVE-2023-20198
CVE-2024-33587
CVE-2024-33449
CVE-2024-4308
HTML injection
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »