Where
-Infinity
0

giteaGitea: Cross-Repository Authorization Bypass via Release Attachment Linking Leads to Private Attachment Disclosure

Risk 47
Severity
9.1
EPSS
0.03%
First published (updated )

giteaIn Gitea before 1.21.2, an anonymous user can visit a private user's project.

Risk 30
Severity
5.8
First published (updated )

giteaGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within on…

Risk 27
Severity
5.3
First published (updated )

giteaXSS

Risk 34
Severity
5.4
First published (updated )

giteaGitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope l…

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

giteaGitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an…

Risk 67
Severity
8.2
First published (updated )

The RegisterIllicit crypto-miners pouncing on lazy DevOps configs that leave clouds vulnerable

First published (updated )

go/code.gitea.io/giteaIn Gitea through 1.17.1, repo cloning can occur in the migration function.

Risk 40
Severity
6.5
First published (updated )

Gitea Gitea JenkinsIn Jenkins Gitea Plugin 1.4.4 and earlier, the implementation of Gitea personal access tokens did no…

Risk 22
Severity
4.3
First published (updated )

go/code.gitea.io/giteaIn Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to imprope…

Risk 40
Severity
6.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaCross-site Scripting (XSS) - Stored in go-gitea/gitea

Risk 34
Severity
5.4
First published (updated )

Gitea GiteaGitea before 1.16.7 does not escape git fetch remote.

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaAn arbitrary file deletion vulnerability in Gitea v1.16.3 allows attackers to cause a Denial of Serv…

Risk 43
Severity
7.5
First published (updated )

go/code.gitea.io/giteaOpen Redirect on login in go-gitea/gitea

Risk 46
Severity
7.2
First published (updated )

Gitea GiteaPath Traversal

Risk 27
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaMissing Authorization in go-gitea/gitea

Risk 48
Severity
7.1
First published (updated )

go/code.gitea.io/giteaAn Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious use…

Risk 87
Severity
9.8
First published (updated )

Gitea GiteaAn issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to cli…

Risk 86
Severity
9.8
First published (updated )

Gitea GiteaXSS

Risk 38
Severity
6.1
First published (updated )

Gitea GiteaGitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal U…

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gitea GiteaGitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referenc…

Risk 86
Severity
9.8
First published (updated )

go/github.com/go-gitea/giteaCSRF

Risk 78
Severity
8.8
First published (updated )

Gitea GiteaSSRF

Risk 43
Severity
7.5
First published (updated )

Gitea GiteaXSS

Risk 34
Severity
5.4
First published (updated )

go/github.com/go-gitea/giteaGitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP …

Risk 89
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/code.gitea.io/giteaOS Command Injection

Risk 69
Severity
7.2
First published (updated )

Gitea GiteaAn issue was discovered in Gitea through 1.11.5. An attacker can trigger a deadlock by initiating a …

Risk 43
Severity
7.5
First published (updated )

go/code.gitea.io/giteaXSS

Risk 38
Severity
6.1
First published (updated )

Gitea GiteaXSS

Risk 39
Severity
6.1
First published (updated )

maven/org.jenkins-ci.plugins:giteaJenkins Gitea Plugin prior to 1.1.2 did not implement trusted revisions, allowing attackers without …

Risk 44
Severity
7.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203