Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gogs vulnerabilities and exploits
(subscribe to this query)
7.5
CVSSv2
CVE-2014-8681
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.6.x prior to 0.5.6.1025 Beta allows remote malicious users to execute arbitrary SQL commands via the label parameter to user/repos/issues.
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
Gogits Gogs 0.3.1-9
1 EDB exploit
4.3
CVSSv2
CVE-2014-8683
Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.8 allows remote malicious users to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.
Gogits Gogs 0.3.1-9
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
7.5
CVSSv2
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.6.1105 Beta allow remote malicious users to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/re...
Gogits Gogs 0.3.1-9
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
1 EDB exploit
7.5
CVSSv2
CVE-2018-18925
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
Gogs Gogs
3 Github repositories
6.5
CVSSv2
CVE-2022-0415
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs before 0.12.6.
Gogs Gogs
1 Github repository
5
CVSSv2
CVE-2022-0870
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.5.
Gogs Gogs
5.8
CVSSv2
CVE-2022-0871
Missing Authorization in GitHub repository gogs/gogs before 0.12.5.
Gogs Gogs
3.5
CVSSv2
CVE-2022-31038
Gogs is an open source self-hosted Git service. In versions of gogs before 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which saniti...
Gogs Gogs
NA
CVE-2022-2024
OS Command Injection in GitHub repository gogs/gogs before 0.12.11.
Gogs Gogs
7.5
CVSSv2
CVE-2022-1986
OS Command Injection in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-4040
privilege escalation
CVE-2024-4112
CVE-2024-32872
man-in-the-middle
CVE-2024-32788
bypass
CVE-2024-3400
CVE-2024-28976
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »