Software
gogs
Aggregate across all detected versions
Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
56
known CVEs
Top Countries
No geolocated hosts.
Top ASNs
No attributed hosts.
CVE Matches
| CVE | CVSS | Severity | Summary |
|---|---|---|---|
| CVE-2024-56731 | 10.0 | N/A | Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command... |
| CVE-2024-39930 | 9.9 | N/A | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can e... |
| CVE-2024-39931 | 9.9 | N/A | Gogs through 0.13.0 allows deletion of internal files. |
| CVE-2024-39932 | 9.9 | N/A | Gogs through 0.13.0 allows argument injection during the previewing of changes. |
| CVE-2018-18925 | 9.8 | N/A | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session... |
| CVE-2019-14544 | 9.8 | N/A | routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks. |
| CVE-2022-1884 | 9.8 | N/A | A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper valid... |
| CVE-2022-1986 | 9.8 | N/A | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-2024 | 9.8 | N/A | OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11. |
| CVE-2024-54148 | 9.8 | N/A | Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the ser... |
| CVE-2025-64111 | 9.8 | N/A | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update fil... |
| CVE-2026-25242 | 9.8 | N/A | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSignin... |
| CVE-2026-25921 | 9.3 | N/A | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS ob... |
| CVE-2022-0871 | 9.1 | N/A | Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5. |
| CVE-2022-1992 | 9.1 | N/A | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2022-32174 | 9.0 | N/A | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover. |
| CVE-2018-15193 | 8.8 | N/A | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link. |
| CVE-2019-10348 | 8.8 | N/A | Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission... |
| CVE-2021-32546 | 8.8 | N/A | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (registered u... |
| CVE-2022-0415 | 8.8 | N/A | Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6. |
| CVE-2024-44625 | 8.8 | N/A | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go. |
| CVE-2024-55947 | 8.8 | N/A | Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. Th... |
| CVE-2025-64175 | 8.8 | N/A | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-acc... |
| CVE-2025-8110 | 8.8 | N/A | Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code. |
| CVE-2026-25232 | 8.8 | N/A | Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator w... |
| CVE-2026-26022 | 8.7 | N/A | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue descr... |
| CVE-2018-15192 | 8.6 | N/A | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services. |
| CVE-2018-16409 | 8.6 | N/A | In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF. |
| CVE-2022-1993 | 8.1 | N/A | Path Traversal in GitHub repository gogs/gogs prior to 0.12.9. |
| CVE-2026-24135 | 8.1 | N/A | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The v... |
| CVE-2024-39933 | 7.7 | N/A | Gogs through 0.13.0 allows argument injection during the tagging of a new release. |
| CVE-2014-8681 | 7.5 | HIGH | SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remo... |
| CVE-2014-8682 | 7.5 | HIGH | Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL... |
| CVE-2018-20303 | 7.5 | N/A | In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessio... |
| CVE-2026-26194 | 7.3 | N/A | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user controlled... |
| CVE-2026-26276 | 7.3 | N/A | Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone name, and... |
| CVE-2020-15867 | 7.2 | N/A | The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook fea... |
| CVE-2020-14958 | 6.5 | N/A | In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check. |
| CVE-2022-1285 | 6.5 | N/A | Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8. |
| CVE-2026-22592 | 6.5 | N/A | Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted b... |