Check-Host.cc

Software

gogs

Aggregate across all detected versions

Total Hosts
0
distinct hosts
Versions Seen
0
Countries
0
Known CVEs
56
known CVEs

Top Countries

No geolocated hosts.

Top ASNs

No attributed hosts.

CVE Matches

CVE CVSS Severity Summary
CVE-2024-56731 10.0 N/A Gogs is an open source self-hosted Git service. Prior to version 0.13.3, it's still possible to delete files under the .git directory and achieve remote command...
CVE-2024-39930 9.9 N/A The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can e...
CVE-2024-39931 9.9 N/A Gogs through 0.13.0 allows deletion of internal files.
CVE-2024-39932 9.9 N/A Gogs through 0.13.0 allows argument injection during the previewing of changes.
CVE-2018-18925 9.8 N/A Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session...
CVE-2019-14544 9.8 N/A routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
CVE-2022-1884 9.8 N/A A remote command execution vulnerability exists in gogs/gogs versions <=0.12.7 when deployed on a Windows server. The vulnerability arises due to improper valid...
CVE-2022-1986 9.8 N/A OS Command Injection in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-2024 9.8 N/A OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
CVE-2024-54148 9.8 N/A Gogs is an open source self-hosted Git service. A malicious user is able to commit and edit a crafted symlink file to a repository to gain SSH access to the ser...
CVE-2025-64111 9.8 N/A Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-56731, it's still possible to update fil...
CVE-2026-25242 9.8 N/A Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints by default. When the global RequireSignin...
CVE-2026-25921 9.3 N/A Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos leads to supply-chain attack, all LFS ob...
CVE-2022-0871 9.1 N/A Missing Authorization in GitHub repository gogs/gogs prior to 0.12.5.
CVE-2022-1992 9.1 N/A Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2022-32174 9.0 N/A In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CVE-2018-15193 8.8 N/A A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
CVE-2019-10348 8.8 N/A Jenkins Gogs Plugin stored credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission...
CVE-2021-32546 8.8 N/A Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely. An unprivileged attacker (registered u...
CVE-2022-0415 8.8 N/A Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
CVE-2024-44625 8.8 N/A Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
CVE-2024-55947 8.8 N/A Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. Th...
CVE-2025-64175 8.8 N/A Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not scope codes by user, enabling cross-acc...
CVE-2025-8110 8.8 N/A Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
CVE-2026-25232 8.8 N/A Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability which allows any repository collaborator w...
CVE-2026-26022 8.7 N/A Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerability exists in the comment and issue descr...
CVE-2018-15192 8.6 N/A An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
CVE-2018-16409 8.6 N/A In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
CVE-2022-1993 8.1 N/A Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
CVE-2026-24135 8.1 N/A Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in the updateWikiPage function of Gogs. The v...
CVE-2024-39933 7.7 N/A Gogs through 0.13.0 allows argument injection during the tagging of a new release.
CVE-2014-8681 7.5 HIGH SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remo...
CVE-2014-8682 7.5 HIGH Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL...
CVE-2018-20303 7.5 N/A In pkg/tool/path.go in Gogs before 0.11.82.1218, a directory traversal in the file-upload functionality can allow an attacker to create a file under data/sessio...
CVE-2026-26194 7.3 N/A Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting a release can fail if a user controlled...
CVE-2026-26276 7.3 N/A Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payload in a repository’s Milestone name, and...
CVE-2020-15867 7.2 N/A The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook fea...
CVE-2020-14958 6.5 N/A In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
CVE-2022-1285 6.5 N/A Server-Side Request Forgery (SSRF) in GitHub repository gogs/gogs prior to 0.12.8.
CVE-2026-22592 6.5 N/A Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attack. If one of the repo files is deleted b...