Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gogs gogs vulnerabilities and exploits
(subscribe to this query)
446
VMScore
CVE-2022-0870
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.5.
Gogs Gogs
516
VMScore
CVE-2022-0871
Missing Authorization in GitHub repository gogs/gogs before 0.12.5.
Gogs Gogs
NA
CVE-2022-2024
OS Command Injection in GitHub repository gogs/gogs before 0.12.11.
Gogs Gogs
578
VMScore
CVE-2022-0415
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs before 0.12.6.
Gogs Gogs
1 Github repository
312
VMScore
CVE-2022-1464
Stored xss bug in GitHub repository gogs/gogs before 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .
Gogs Gogs
578
VMScore
CVE-2020-15867
The git hook feature in Gogs 0.5.5 up to and including 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a user who does not have administrative privileges. NOTE: because this is mentioned in th...
Gogs Gogs
383
VMScore
CVE-2020-9329
Gogs up to and including 0.11.91 allows malicious users to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Gogs Gogs
446
VMScore
CVE-2018-20303
In pkg/tool/path.go in Gogs prior to 0.11.82.1218, a directory traversal in the file-upload functionality can allow an malicious user to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
Gogs Gogs
2 Github repositories
516
VMScore
CVE-2018-15178
Open redirect vulnerability in Gogs prior to 0.12 allows remote malicious users to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go...
Gogs Gogs
668
VMScore
CVE-2018-18925
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.
Gogs Gogs
3 Github repositories
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-49333
CVE-2024-33901
CVE-2024-36001
CVE-2024-2835
firewall
XPath injection
authentication bypass
CVE-2024-22120
CVE-2024-32002
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »