Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gogs gogs vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2022-32174
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
Gogs Gogs
6.5
CVSSv2
CVE-2020-15867
The git hook feature in Gogs 0.5.5 up to and including 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in th...
Gogs Gogs
6.5
CVSSv2
CVE-2021-32546
Missing input validation in internal/db/repo_editor.go in Gogs prior to 0.12.8 allows an malicious user to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command Execution, because that...
Gogs Gogs
7.5
CVSSv2
CVE-2022-1986
OS Command Injection in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
6.4
CVSSv2
CVE-2022-1992
Path Traversal in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
5.5
CVSSv2
CVE-2022-1993
Path Traversal in GitHub repository gogs/gogs before 0.12.9.
Gogs Gogs
4.3
CVSSv2
CVE-2020-9329
Gogs up to and including 0.11.91 allows malicious users to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Gogs Gogs
3.5
CVSSv2
CVE-2022-1464
Stored xss bug in GitHub repository gogs/gogs before 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .
Gogs Gogs
4.3
CVSSv2
CVE-2022-1285
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.8.
Gogs Gogs
6.5
CVSSv2
CVE-2022-0415
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs before 0.12.6.
Gogs Gogs
1 Github repository
CVSSv2
CVSSv2
CVSSv3
VMScore
Recommendations:
type confusion
CVE-2024-20360
CVE-2021-47559
XXE
CVE-2024-5229
CVE-2021-47543
CVE-2021-47571
SSTI
CVE-2024-4978
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »