Gogs
16 known vulnerabilities
Top Products
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, an attacker can store an HTML/JavaScript payloa
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, gogs api still accepts tokens in url params lik
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, stored xss is still possible through unsafe tem
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, there's a security issue in gogs where deleting
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, a stored cross-site scripting (XSS) vulnerabili
Gogs is an open source self-hosted Git service. Prior to version 0.14.2, overwritable LFS object across different repos
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below expose unauthenticated file upload endpoints b
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have an access control bypass vulnerability wh
Gogs is an open source self-hosted Git service. Versions 0.13.4 and below have a broken access control vulnerability whi
Gogs is an open source self-hosted Git service. In versions 0.13.4 and below, the DeleteComment API does not verify that
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, a path traversal vulnerability exists in th
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, there is an arbitrary file read/write via p
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, the endpoint "PUT /repos/:owner/:repo/conte
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, an authenticated user can cause a DOS attac
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, Gogs’ 2FA recovery code validation does not
Gogs is an open source self-hosted Git service. In version 0.13.3 and prior, due to the insufficient patch for CVE-2024-
Frequently Asked Questions
How many CVEs affect Gogs?
Gogs has 16 CVE records in our database, including 3 critical and 6 high severity vulnerabilities.
What are the most severe Gogs vulnerabilities?
Gogs has 3 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Gogs vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Gogs products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Gogs Vulnerabilities
CyberStrike scans your infrastructure for Gogs vulnerabilities and provides real-time remediation guidance.
Get Started