GO-2022-0369: Gogs vulnerable to improper PAM authorization handling in gogs.io/gogs
GO-2022-0473: Cross site scripting via cookies in gogs in gogs.io/gogs
GO-2022-0483: Cross-site Scripting vulnerability in repository issue list in Gogs in gogs.io/gogs
GO-2022-0554: Unrestricted Upload of File with Dangerous Type in Gogs in gogs.io/gogs
GO-2022-0556: OS Command Injection in file editor in Gogs in gogs.io/gogs
GO-2022-0562: Path Traversal in Git HTTP endpoints in Gogs in gogs.io/gogs
GO-2022-0570: Path Traversal in file editor on Windows in Gogs in gogs.io/gogs
GO-2022-0583: Server-Side Request Forgery in gogs webhook in gogs.io/gogs
GO-2022-1060: Gogs vulnerable to Cross-site Scripting in gogs.io/gogs
GO-2023-1596: Gogs OS Command Injection vulnerability in gogs.io/gogs
GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
GO-2024-3275: Unpatched Remote Code Execution in Gogs in gogs.io/gogs
GO-2024-3355: Remote Command Execution in file editing in gogs in gogs.io/gogs
GO-2024-3356: Path Traversal in file update API in gogs in gogs.io/gogs
GO-2025-3776: Gogs allows deletion of internal files which leads to remote command execution in gogs.io/gogs
GO-2025-3778: Gogs XSS allowed by stored call in PDF renderer in gogs.io/gogs
GO-2025-4225: Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs
GO-2026-4448: Gogs's update .git/config file allows remote command execution in gogs.io/gogs
GO-2026-4450: Gogs user can update repository content with read-only permission in gogs.io/gogs
GO-2026-4451: Gogs has a Denial of Service issue in gogs.io/gogs
GO-2026-4452: Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs
GO-2026-4453: Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs
GO-2026-4454: Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs
GO-2026-4457: Gogs has authorization bypass in repository deletion API in gogs.io/gogs
GO-2026-4498: Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs
GO-2026-4499: Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs
GO-2026-4500: Unauthenticated File Upload in Gogs in gogs.io/gogs
GO-2026-4501: Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs
GO-2026-4616: Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs
GO-2026-4617: Gogs: Release tag option injection in release deletion in gogs.io/gogs
GO-2026-4618: Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs
GO-2026-4619: Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs
GO-2026-4620: Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs
GO-2026-4627: Gogs: DOM-based XSS via milestone selection in gogs.io/gogs