Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gogs vulnerabilities and exploits
(subscribe to this query)
4.3
CVSSv2
CVE-2020-9329
Gogs up to and including 0.11.91 allows malicious users to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Gogs Gogs
4.3
CVSSv2
CVE-2022-1285
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.8.
Gogs Gogs
NA
CVE-2022-2024
OS Command Injection in GitHub repository gogs/gogs before 0.12.11.
Gogs Gogs
6.5
CVSSv2
CVE-2021-32546
Missing input validation in internal/db/repo_editor.go in Gogs prior to 0.12.8 allows an malicious user to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command Execution, because that...
Gogs Gogs
6.5
CVSSv2
CVE-2020-15867
The git hook feature in Gogs 0.5.5 up to and including 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in th...
Gogs Gogs
3.5
CVSSv2
CVE-2022-31038
Gogs is an open source self-hosted Git service. In versions of gogs before 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which saniti...
Gogs Gogs
6.5
CVSSv2
CVE-2022-0415
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs before 0.12.6.
Gogs Gogs
1 Github repository
NA
CVE-2022-32174
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
Gogs Gogs
7.5
CVSSv2
CVE-2022-1986
OS Command Injection in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
5.5
CVSSv2
CVE-2022-1993
Path Traversal in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2022-48700
CVE-2022-48689
CVE-2024-27956
CVE-2023-6363
SQL
NULL pointer dereference
CVE-2023-41830
CVE-2015-2051
arbitrary
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »