gogs records
49 published records for vendor gogs.
Researcher profile
- Entered KEV
- 1 · 2%
- Weaponized
- 2 · 4.1%
- Pre-auth RCE
- 6
- With a fix record
- 85.7%
- Median publish → KEV
- 33 days
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')9
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')7
- CWE-862 Missing Authorization5
- CWE-918 Server-Side Request Forgery (SSRF)4
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')4
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')3
The weakness classes this vendor ships most often: where to look.
CWEAll records
49 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
90Now | CVE-2025-8110Weaponized | File overwrite in file update API in Gogsgogs · gogs · CWE-22 | High8.7 | KEV | 85.2% | Dec 10, 2025 |
68This week | CVE-2022-2024No exploit | OS Command Injection in gogs/gogsgogs · gogs · CWE-78 | Critical9.8 | — | 97.8% | Feb 25, 2023 |
57Plan | CVE-2024-55947Proof of concept | Gogs has a Path Traversal in file update APIgogs · gogs · CWE-22 | High8.7 | — | 77.8% | Dec 23, 2024 |
55Plan | CVE-2022-0415Proof of concept | Remote Command Execution in uploading repository file in gogs/gogsgogs · gogs · CWE-20 | High8.8 | — | 65.2% | Mar 21, 2022 |
55Plan | CVE-2024-39931No exploit | Gogs through 0.13.0 allows deletion of internal files.gogs · gogs · CWE-552 | Critical9.9 | — | 52.7% | Jul 4, 2024 |
54Plan | CVE-2020-15867Weaponized | The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.gogs · gogs | High7.2 | — | 87.4% | Oct 16, 2020 |
53Plan | CVE-2022-32174No exploit | In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.gogs · gogs · CWE-79 | Critical9.0 | — | 58.0% | Oct 11, 2022 |
48Plan | CVE-2018-18925Proof of concept | Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery gogs · gogs · CWE-384 | Critical9.8 | — | 31.1% | Nov 4, 2018 |
44Plan | CVE-2024-39932No exploit | Gogs through 0.13.0 allows argument injection during the previewing of changes.gogs · gogs · CWE-94 | Critical9.9 | — | 17.3% | Jul 4, 2024 |
43Plan | CVE-2022-1993No exploit | Path Traversal in gogs/gogsgogs · gogs · CWE-22 | High8.1 | — | 36.3% | Jun 9, 2022 |
41Plan | CVE-2024-39930Proof of concept | The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.gogs · gogs · CWE-88 | Critical9.9 | — | 7.7% | Jul 4, 2024 |
40Plan | CVE-2024-44625Proof of concept | Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.gogs · gogs · CWE-22 | High8.8 | — | 16.5% | Nov 15, 2024 |
40Plan | CVE-2022-1986No exploit | OS Command Injection in gogs/gogsgogs · gogs · CWE-78 | Critical9.8 | — | 4.5% | Jun 9, 2022 |
40Plan | CVE-2022-1884No exploit | Remote Command Execution in gogs/gogsgogs · gogs · CWE-78 | Critical9.8 | — | 1.8% | Nov 15, 2024 |
39Monitor | CVE-2019-14544No exploit | routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.gogs · gogs · CWE-862 | Critical9.8 | — | 1.5% | Aug 2, 2019 |
39Monitor | CVE-2024-56731No exploit | Gogs deletion of internal files allows remote command executiongogs · gogs · CWE-552 | Critical9.8 | — | 1.2% | Jun 24, 2025 |
37Monitor | CVE-2022-1992No exploit | Path Traversal in gogs/gogsgogs · gogs · CWE-22 | Critical9.1 | — | 2.3% | Jun 9, 2022 |
37Monitor | CVE-2025-64111No exploit | Gogs's update .git/config file allows remote command executiongogs · gogs · CWE-78 | Critical9.3 | — | 1.3% | Feb 6, 2026 |
37Monitor | CVE-2026-25921No exploit | Gogs: Cross-repository LFS object overwrite via missing content hash verificationgogs · gogs · CWE-345 | Critical9.3 | — | 0.3% | Mar 5, 2026 |
36Monitor | CVE-2021-32546No exploit | Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.gogs · gogs | High8.8 | — | 2.1% | Jun 2, 2022 |
36Monitor | CVE-2022-0871No exploit | Missing Authorization in gogs/gogsgogs · gogs · CWE-862 | Critical9.1 | — | 1.2% | Mar 11, 2022 |
35Monitor | CVE-2018-15192No exploit | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.gitea · gitea · CWE-918 | High8.6 | — | 2.1% | Aug 7, 2018 |
35Monitor | CVE-2018-15193No exploit | A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / ligogs · gogs · CWE-352 | High8.8 | — | 0.8% | Aug 7, 2018 |
35Monitor | CVE-2026-26194No exploit | Gogs: Release tag option injection in release deletiongogs · gogs · CWE-88 | High8.8 | — | 0.5% | Mar 5, 2026 |
34Monitor | CVE-2018-16409No exploit | In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.gogs · gogs · CWE-918 | High8.6 | — | 1.3% | Sep 3, 2018 |
- CVE-2025-811090Now
File overwrite in file update API in Gogs
HighCVSS 8.7KEVWeaponizedEPSS 85%gogs · gogsDec 10, 2025
- CVE-2022-202468This week
OS Command Injection in gogs/gogs
CriticalCVSS 9.8No exploitEPSS 98%gogs · gogsFeb 25, 2023
- CVE-2024-5594757Plan
Gogs has a Path Traversal in file update API
HighCVSS 8.7Proof of conceptEPSS 78%gogs · gogsDec 23, 2024
- CVE-2022-041555Plan
Remote Command Execution in uploading repository file in gogs/gogs
HighCVSS 8.8Proof of conceptEPSS 65%gogs · gogsMar 21, 2022
- CVE-2024-3993155Plan
Gogs through 0.13.0 allows deletion of internal files.
CriticalCVSS 9.9No exploitEPSS 53%gogs · gogsJul 4, 2024
- CVE-2020-1586754Plan
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution.
HighCVSS 7.2WeaponizedEPSS 87%gogs · gogsOct 16, 2020
- CVE-2022-3217453Plan
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
CriticalCVSS 9.0No exploitEPSS 58%gogs · gogsOct 11, 2022
- CVE-2018-1892548Plan
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery
CriticalCVSS 9.8Proof of conceptEPSS 31%gogs · gogsNov 4, 2018
- CVE-2024-3993244Plan
Gogs through 0.13.0 allows argument injection during the previewing of changes.
CriticalCVSS 9.9No exploitEPSS 17%gogs · gogsJul 4, 2024
- CVE-2022-199343Plan
Path Traversal in gogs/gogs
HighCVSS 8.1No exploitEPSS 36%gogs · gogsJun 9, 2022
- CVE-2024-3993041Plan
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution.
CriticalCVSS 9.9Proof of conceptEPSS 8%gogs · gogsJul 4, 2024
- CVE-2024-4462540Plan
Gogs <=0.13.0 is vulnerable to Directory Traversal via the editFilePost function of internal/route/repo/editor.go.
HighCVSS 8.8Proof of conceptEPSS 17%gogs · gogsNov 15, 2024
- CVE-2022-198640Plan
OS Command Injection in gogs/gogs
CriticalCVSS 9.8No exploitEPSS 4%gogs · gogsJun 9, 2022
- CVE-2022-188440Plan
Remote Command Execution in gogs/gogs
CriticalCVSS 9.8No exploitEPSS 2%gogs · gogsNov 15, 2024
- CVE-2019-1454439Monitor
routes/api/v1/api.go in Gogs 0.11.86 lacks permission checks for routes: deploy keys, collaborators, and hooks.
CriticalCVSS 9.8No exploitEPSS 2%gogs · gogsAug 2, 2019
- CVE-2024-5673139Monitor
Gogs deletion of internal files allows remote command execution
CriticalCVSS 9.8No exploitEPSS 1%gogs · gogsJun 24, 2025
- CVE-2022-199237Monitor
Path Traversal in gogs/gogs
CriticalCVSS 9.1No exploitEPSS 2%gogs · gogsJun 9, 2022
- CVE-2025-6411137Monitor
Gogs's update .git/config file allows remote command execution
CriticalCVSS 9.3No exploitEPSS 1%gogs · gogsFeb 6, 2026
- CVE-2026-2592137Monitor
Gogs: Cross-repository LFS object overwrite via missing content hash verification
CriticalCVSS 9.3No exploitEPSS 0%gogs · gogsMar 5, 2026
- CVE-2021-3254636Monitor
Missing input validation in internal/db/repo_editor.go in Gogs before 0.12.8 allows an attacker to execute code remotely.
HighCVSS 8.8No exploitEPSS 2%gogs · gogsJun 2, 2022
- CVE-2022-087136Monitor
Missing Authorization in gogs/gogs
CriticalCVSS 9.1No exploitEPSS 1%gogs · gogsMar 11, 2022
- CVE-2018-1519235Monitor
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
HighCVSS 8.6No exploitEPSS 2%gitea · giteaAug 7, 2018
- CVE-2018-1519335Monitor
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / li
HighCVSS 8.8No exploitEPSS 1%gogs · gogsAug 7, 2018
- CVE-2026-2619435Monitor
Gogs: Release tag option injection in release deletion
HighCVSS 8.8No exploitEPSS 1%gogs · gogsMar 5, 2026
- CVE-2018-1640934Monitor
In Gogs 0.11.53, an attacker can use migrate to send arbitrary HTTP GET requests, leading to SSRF.
HighCVSS 8.6No exploitEPSS 1%gogs · gogsSep 3, 2018