Skip to content
Noroxi

gogs records

49 published records for vendor gogs.

All records

49 records
  • File overwrite in file update API in Gogs

    HighCVSS 8.7KEVWeaponizedEPSS 85%

    gogs · gogsDec 10, 2025

  • CVE-2022-2024
    68This week

    OS Command Injection in gogs/gogs

    CriticalCVSS 9.8No exploitEPSS 98%

    gogs · gogsFeb 25, 2023

  • Gogs has a Path Traversal in file update API

    HighCVSS 8.7Proof of conceptEPSS 78%

    gogs · gogsDec 23, 2024

  • Remote Command Execution in uploading repository file in gogs/gogs

    HighCVSS 8.8Proof of conceptEPSS 65%

    gogs · gogsMar 21, 2022

  • Gogs through 0.13.0 allows deletion of internal files.

    CriticalCVSS 9.9No exploitEPSS 53%

    gogs · gogsJul 4, 2024

  • The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.

    HighCVSS 7.2WeaponizedEPSS 87%

    gogs · gogsOct 16, 2020

  • In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

    CriticalCVSS 9.0No exploitEPSS 58%

    gogs · gogsOct 11, 2022

  • Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery

    CriticalCVSS 9.8Proof of conceptEPSS 31%

    gogs · gogsNov 4, 2018

  • Gogs through 0.13.0 allows argument injection during the previewing of changes.

    CriticalCVSS 9.9No exploitEPSS 17%

    gogs · gogsJul 4, 2024

  • Path Traversal in gogs/gogs

    HighCVSS 8.1No exploitEPSS 36%

    gogs · gogsJun 9, 2022

  • The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.

    CriticalCVSS 9.9Proof of conceptEPSS 8%

    gogs · gogsJul 4, 2024

  • Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.

    HighCVSS 8.8Proof of conceptEPSS 17%

    gogs · gogsNov 15, 2024

  • OS Command Injection in gogs/gogs

    CriticalCVSS 9.8No exploitEPSS 4%

    gogs · gogsJun 9, 2022

  • Remote Command Execution in gogs/gogs

    CriticalCVSS 9.8No exploitEPSS 2%

    gogs · gogsNov 15, 2024

  • routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.

    CriticalCVSS 9.8No exploitEPSS 2%

    gogs · gogsAug 2, 2019

  • Gogs deletion of internal files allows remote command execution

    CriticalCVSS 9.8No exploitEPSS 1%

    gogs · gogsJun 24, 2025

  • CVE-2022-1992
    37Monitor

    Path Traversal in gogs/gogs

    CriticalCVSS 9.1No exploitEPSS 2%

    gogs · gogsJun 9, 2022

  • Gogs's update .git/config file allows remote command execution

    CriticalCVSS 9.3No exploitEPSS 1%

    gogs · gogsFeb 6, 2026

  • Gogs: Cross-repository LFS object overwrite via missing content hash verification

    CriticalCVSS 9.3No exploitEPSS 0%

    gogs · gogsMar 5, 2026

  • Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.

    HighCVSS 8.8No exploitEPSS 2%

    gogs · gogsJun 2, 2022

  • CVE-2022-0871
    36Monitor

    Missing Authorization in gogs/gogs

    CriticalCVSS 9.1No exploitEPSS 1%

    gogs · gogsMar 11, 2022

  • An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

    HighCVSS 8.6No exploitEPSS 2%

    gitea · giteaAug 7, 2018

  • A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / li

    HighCVSS 8.8No exploitEPSS 1%

    gogs · gogsAug 7, 2018

  • Gogs: Release tag option injection in release deletion

    HighCVSS 8.8No exploitEPSS 1%

    gogs · gogsMar 5, 2026

  • In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.

    HighCVSS 8.6No exploitEPSS 1%

    gogs · gogsSep 3, 2018