Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
gogs gogs vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2014-8681
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.6.x prior to 0.5.6.1025 Beta allows remote malicious users to execute arbitrary SQL commands via the label parameter to user/repos/issues.
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
Gogits Gogs 0.3.1-9
1 EDB exploit
NA
CVE-2014-8682
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.6.1105 Beta allow remote malicious users to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/re...
Gogits Gogs 0.3.1-9
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
1 EDB exploit
NA
CVE-2014-8683
Cross-site scripting (XSS) vulnerability in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 up to and including 0.5.x prior to 0.5.8 allows remote malicious users to inject arbitrary web script or HTML via the text parameter to api/v1/markdown.
Gogits Gogs 0.3.1-9
Gogits Gogs 0.4.1
Gogits Gogs 0.4.2
Gogits Gogs 0.5.0
Gogits Gogs 0.5.2
Gogits Gogs
7.5
CVSSv3
CVE-2018-20303
In pkg/tool/path.go in Gogs prior to 0.11.82.1218, a directory traversal in the file-upload functionality can allow an malicious user to create a file under data/sessions on the server, a similar issue to CVE-2018-18925.
Gogs Gogs
2 Github repositories
5.4
CVSSv3
CVE-2022-31038
Gogs is an open source self-hosted Git service. In versions of gogs before 0.12.9 `DisplayName` does not filter characters input from users, which leads to an XSS vulnerability when directly displayed in the issue list. This issue has been resolved in commit 155cae1d which saniti...
Gogs Gogs
6.5
CVSSv3
CVE-2022-1285
Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs before 0.12.8.
Gogs Gogs
9
CVSSv3
CVE-2022-32174
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
Gogs Gogs
5.9
CVSSv3
CVE-2020-9329
Gogs up to and including 0.11.91 allows malicious users to violate the admin-specified repo-creation policy due to an internal/db/repo.go race condition.
Gogs Gogs
8.8
CVSSv3
CVE-2021-32546
Missing input validation in internal/db/repo_editor.go in Gogs prior to 0.12.8 allows an malicious user to execute code remotely. An unprivileged attacker (registered user) can overwrite the Git configuration in his repository. This leads to Remote Command Execution, because that...
Gogs Gogs
9.8
CVSSv3
CVE-2022-2024
OS Command Injection in GitHub repository gogs/gogs before 0.12.11.
Gogs Gogs
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30051
remote
CVE-2024-27954
CVE-2023-51483
CVE-2023-47782
SSRF
CVE-2024-24715
CVE-2023-52424
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
1
2
3
4
NEXT »