gogs.io/gogs vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-26196Mediumgogs.io/gogs: Gogs: Access tokens get exposed through URL params in API requestsCVE-2026-26195Mediumgogs.io/gogs: Gogs: Stored XSS in branch and wiki views through author and committer namesCVE-2026-26194Highgogs.io/gogs: Gogs: Release tag option injection in release deletionCVE-2026-26022Highgogs.io/gogs: Gogs: Stored XSS via data URI in issue commentsCVE-2026-25921Criticalgogs.io/gogs: Gogs: Cross-repository LFS object overwrite via missing content hash verificationCVE-2026-25242Mediumgogs.io/gogs: Unauthenticated File Upload in GogsCVE-2026-25232Highgogs.io/gogs: Gogs has a Protected Branch Deletion Bypass in Web InterfaceCVE-2026-25229Mediumgogs.io/gogs: Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in GogsCVE-2026-25120Mediumgogs.io/gogs: Gogs Allows Cross-Repository Comment Deletion via DeleteCommentCVE-2025-65852Mediumgogs.io/gogs: Gogs has authorization bypass in repository deletion APIGHSA-26GQ-GRMH-6XM6Highgogs.io/gogs: Gogs vulnerable to Stored XSS via Mermaid diagramsCVE-2026-24135Highgogs.io/gogs: Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page updateCVE-2026-23633Mediumgogs.io/gogs: Gogs has arbitrary file read/write via Path Traversal in Git hook editingCVE-2026-23632Mediumgogs.io/gogs: Gogs user can update repository content with read-only permissionCVE-2026-22592Mediumgogs.io/gogs: Gogs has a Denial of Service issueCVE-2025-64175Highgogs.io/gogs: Gogs Vulnerable to 2FA Bypass via Recovery CodeCVE-2025-64111Criticalgogs.io/gogs: Gogs's update .git/config file allows remote command executionCVE-2025-8110Highgogs.io/gogs: Gogs vulnerable to a bypass of CVE-2024-55947CVE-2025-47943Mediumgithub.com/gogs/gogs: Gogs XSS allowed by stored call in PDF rendererCVE-2024-56731Criticalgogs.io/gogs: Gogs allows deletion of internal files which leads to remote command executionCVE-2024-39930Criticalgogs.io/gogs: Gogs has an argument Injection in the built-in SSH serverCVE-2024-39932Criticalgogs.io/gogs: Gogs allows argument injection during the previewing of changesCVE-2024-39931Criticalgogs.io/gogs: Gogs allows deletion of internal filesCVE-2024-39933Highgogs.io/gogs: Gogs allows argument Injection when tagging new releasesCVE-2024-55947Highgogs.io/gogs: Path Traversal in file update API in gogs

Stop the waste.
Protect your environment with Kodem.