Gitea kayıtları
gitea üreticisine ait 54 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %1,9
- Silahlaştırılmış
- 3 · %5,6
- Pre-auth RCE
- 4
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- -1 gün
Tekrar eden sınıflar
- CWE-284 Improper Access Control8
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')8
- CWE-601 URL Redirection to Untrusted Site ('Open Redirect')3
- CWE-862 Missing Authorization3
- CWE-863 Incorrect Authorization3
- CWE-287 Improper Authentication2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
54 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
76Bu hafta | CVE-2026-60004Silahlaştırılmış | Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.gitea · gitea · CWE-94 | Kritik9,8 | KEV | %24,0 | 26 Ağu 2026 |
57Planlayın | CVE-2020-14144Silahlaştırılmış | The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the dogitea · gitea · CWE-78 | Yüksek7,2 | — | %95,4 | 16 Eki 2020 |
56Planlayın | CVE-2022-30781Silahlaştırılmış | Gitea before 1.16.7 does not escape git fetch remote.gitea · gitea · CWE-116 | Yüksek7,5 | — | %87,9 | 16 May 2022 |
51Planlayın | CVE-2019-11229Kavram kanıtı | models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.gitea · gitea | Yüksek8,8 | — | %55,0 | 15 Nis 2019 |
50Planlayın | CVE-2024-6886Kavram kanıtı | Inproper Sanitation of field leading to stored XSSgitea · gitea open source git server · CWE-79 | Kritik10,0 | — | %33,0 | 6 Ağu 2024 |
40Planlayın | CVE-2022-1058Kavram kanıtı | Open Redirect on login in go-gitea/giteagitea · gitea · CWE-601 | Orta6,1 | — | %53,2 | 24 Mar 2022 |
40Planlayın | CVE-2018-18926İstismar yok | Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.gitea · gitea · CWE-384 | Kritik9,8 | — | %3,0 | 4 Kas 2018 |
40Planlayın | CVE-2021-45327İstismar yok | Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.gitea · gitea · CWE-436 | Kritik9,8 | — | %2,1 | 8 Şub 2022 |
40Planlayın | CVE-2019-11576İstismar yok | Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment.gitea · gitea · CWE-287 | Kritik9,8 | — | %1,8 | 27 Nis 2019 |
40Planlayın | CVE-2020-28991İstismar yok | Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (gitea · gitea | Kritik9,8 | — | %1,7 | 23 Kas 2020 |
39İzleyin | CVE-2021-45330İstismar yok | An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and tgitea · gitea · CWE-459 | Kritik9,8 | — | %1,4 | 9 Şub 2022 |
39İzleyin | CVE-2021-45331İstismar yok | An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges.gitea · gitea · CWE-287 | Kritik9,8 | — | %1,4 | 9 Şub 2022 |
39İzleyin | CVE-2022-42968İstismar yok | Gitea before 1.17.3 does not sanitize and escape refs in the git backend.gitea · gitea · CWE-88 | Kritik9,8 | — | %1,2 | 16 Eki 2022 |
36İzleyin | CVE-2026-20912İstismar yok | Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosuregitea · gitea · CWE-284 | Kritik9,1 | — | %0,5 | 22 Oca 2026 |
36İzleyin | CVE-2026-20897İstismar yok | Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)gitea · gitea · CWE-284 | Kritik9,1 | — | %0,5 | 22 Oca 2026 |
36İzleyin | CVE-2026-20750İstismar yok | Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)gitea · gitea · CWE-284 | Kritik9,1 | — | %0,4 | 22 Oca 2026 |
35İzleyin | CVE-2018-15192İstismar yok | An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.gitea · gitea · CWE-918 | Yüksek8,6 | — | %2,1 | 7 Ağu 2018 |
35İzleyin | CVE-2021-45326İstismar yok | Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state altegitea · gitea · CWE-352 | Yüksek8,8 | — | %0,6 | 8 Şub 2022 |
31İzleyin | CVE-2019-10330İstismar yok | Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to changitea · gitea · CWE-862 | Yüksek7,5 | — | %2,1 | 31 May 2019 |
31İzleyin | CVE-2020-13246İstismar yok | An issue was discovered in Gitea through 1.11.5.gitea · gitea · CWE-667 | Yüksek7,5 | — | %2,0 | 20 May 2020 |
31İzleyin | CVE-2021-3382İstismar yok | Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors rgitea · gitea · CWE-787 | Yüksek7,5 | — | %1,8 | 5 Şub 2021 |
30İzleyin | CVE-2019-11228İstismar yok | repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.gitea · gitea · CWE-20 | Yüksek7,5 | — | %1,3 | 15 Nis 2019 |
30İzleyin | CVE-2021-45325İstismar yok | Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.gitea · gitea · CWE-918 | Yüksek7,5 | — | %1,0 | 8 Şub 2022 |
30İzleyin | CVE-2022-27313İstismar yok | An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configurationgitea · gitea | Yüksek7,5 | — | %1,0 | 3 May 2022 |
30İzleyin | CVE-2026-20736İstismar yok | Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Checkgitea · gitea · CWE-284 | Yüksek7,5 | — | %0,4 | 22 Oca 2026 |
- CVE-2026-6000476Bu hafta
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %24gitea · gitea26 Ağu 2026
- CVE-2020-1414457Planlayın
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the do
YüksekCVSS 7,2SilahlaştırılmışEPSS %95gitea · gitea16 Eki 2020
- CVE-2022-3078156Planlayın
Gitea before 1.16.7 does not escape git fetch remote.
YüksekCVSS 7,5SilahlaştırılmışEPSS %88gitea · gitea16 May 2022
- CVE-2019-1122951Planlayın
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
YüksekCVSS 8,8Kavram kanıtıEPSS %55gitea · gitea15 Nis 2019
- CVE-2024-688650Planlayın
Inproper Sanitation of field leading to stored XSS
KritikCVSS 10,0Kavram kanıtıEPSS %33gitea · gitea open source git server6 Ağu 2024
- CVE-2022-105840Planlayın
Open Redirect on login in go-gitea/gitea
OrtaCVSS 6,1Kavram kanıtıEPSS %53gitea · gitea24 Mar 2022
- CVE-2018-1892640Planlayın
Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs.
KritikCVSS 9,8İstismar yokEPSS %3gitea · gitea4 Kas 2018
- CVE-2021-4532740Planlayın
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API.
KritikCVSS 9,8İstismar yokEPSS %2gitea · gitea8 Şub 2022
- CVE-2019-1157640Planlayın
Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment.
KritikCVSS 9,8İstismar yokEPSS %2gitea · gitea27 Nis 2019
- CVE-2020-2899140Planlayın
Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (
KritikCVSS 9,8İstismar yokEPSS %2gitea · gitea23 Kas 2020
- CVE-2021-4533039İzleyin
An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and t
KritikCVSS 9,8İstismar yokEPSS %1gitea · gitea9 Şub 2022
- CVE-2021-4533139İzleyin
An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges.
KritikCVSS 9,8İstismar yokEPSS %1gitea · gitea9 Şub 2022
- CVE-2022-4296839İzleyin
Gitea before 1.17.3 does not sanitize and escape refs in the git backend.
KritikCVSS 9,8İstismar yokEPSS %1gitea · gitea16 Eki 2022
- CVE-2026-2091236İzleyin
Gitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure
KritikCVSS 9,1İstismar yokEPSS %0gitea · gitea22 Oca 2026
- CVE-2026-2089736İzleyin
Gitea Git LFS Lock Deletion Broken Access Control (Cross-Repo IDOR)
KritikCVSS 9,1İstismar yokEPSS %0gitea · gitea22 Oca 2026
- CVE-2026-2075036İzleyin
Gitea Organization Projects Cross-Organization Authorization Bypass via Project ID (IDOR)
KritikCVSS 9,1İstismar yokEPSS %0gitea · gitea22 Oca 2026
- CVE-2018-1519235İzleyin
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
YüksekCVSS 8,6İstismar yokEPSS %2gitea · gitea7 Ağu 2018
- CVE-2021-4532635İzleyin
Cross Site Request Forgery (CSRF) vulnerability exists in Gitea before 1.5.2 via API routes.This can be dangerous especially with state alte
YüksekCVSS 8,8İstismar yokEPSS %1gitea · gitea8 Şub 2022
- CVE-2019-1033031İzleyin
Jenkins Gitea Plugin 1.1.1 and earlier did not implement trusted revisions, allowing attackers without commit access to the Git repo to chan
YüksekCVSS 7,5İstismar yokEPSS %2gitea · gitea31 May 2019
- CVE-2020-1324631İzleyin
An issue was discovered in Gitea through 1.11.5.
YüksekCVSS 7,5İstismar yokEPSS %2gitea · gitea20 May 2020
- CVE-2021-338231İzleyin
Stack buffer overflow vulnerability in gitea 1.9.0 through 1.13.1 allows remote attackers to cause a denial of service (crash) via vectors r
YüksekCVSS 7,5İstismar yokEPSS %2gitea · gitea5 Şub 2021
- CVE-2019-1122830İzleyin
repo/setting.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 does not validate the form.MirrorAddress before calling SaveAddress.
YüksekCVSS 7,5İstismar yokEPSS %1gitea · gitea15 Nis 2019
- CVE-2021-4532530İzleyin
Server Side Request Forgery (SSRF) vulneraility exists in Gitea before 1.7.0 using the OpenID URL.
YüksekCVSS 7,5İstismar yokEPSS %1gitea · gitea8 Şub 2022
- CVE-2022-2731330İzleyin
An arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Service (DoS) via deleting the configuration
YüksekCVSS 7,5İstismar yokEPSS %1gitea · gitea3 May 2022
- CVE-2026-2073630İzleyin
Gitea Web Attachment Deletion: Cross-Repository Unauthorized Deletion via Missing Repo Ownership Check
YüksekCVSS 7,5İstismar yokEPSS %0gitea · gitea22 Oca 2026