Where
-Infinity
0

Gogs GogsGogs: Authorization Bypass in Watch API allows any user to monitor private repository activity

Risk 22
Severity
4.3
First published (updated )

BleepingComputerGogs patches critical zero-day enabling remote code execution

First published (updated )

Gogs GogsGogs: DOM-based XSS via milestone selection

Risk 54
Severity
7.3
First published (updated )

gogsGogs: Access tokens get exposed through URL params in API requests

Risk 33
Severity
6.9
First published (updated )

gogs/gogsGogs: Stored XSS in branch and wiki views through author and committer names

Risk 33
Severity
6.9
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

gogs/gogsGogs: Release tag option injection in release deletion

Risk 60
Severity
8.8
First published (updated )

Gogs GogsGogs: Cross-repository LFS object overwrite via missing content hash verification

Risk 61
Severity
9.3
First published (updated )

Gogs GogsGogs: Stored XSS via data URI in issue comments

Risk 61
Severity
8.7
First published (updated )

go/gogs.io/gogsGogs allows unauthenticated file uploads

Risk 61
Severity
9.8
EPSS
0.05%
First published (updated )

go/gogs.io/gogsGogs has a Protected Branch Deletion Bypass in Web Interface

Risk 56
Severity
8.8
EPSS
0.03%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

go/gogs.io/gogsGogs Authorization Bypass Allows Cross-Repository Label Modification

Risk 27
Severity
6.5
EPSS
0.03%
First published (updated )

go/gogs.io/gogsGogs Allows Cross-Repository Comment Deletion via DeleteComment

Risk 17
Severity
5.1
EPSS
0.02%
First published (updated )

Gogs GogsGogs vulnerable to arbitrary file deletion via path traversal in wiki page update

Risk 43
Severity
8.1
EPSS
0.05%
First published (updated )

Gogs GogsGogs has arbitrary file read/write via path traversal in Git hook editing

Risk 37
Severity
6.5
EPSS
0.07%
First published (updated )

gogsGogs user can update repository content with read-only permission

Risk 27
Severity
6.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

gogs/gogsGogs is Vulnerable to Denial of Service

Risk 38
Severity
6.5
First published (updated )

Gogs GogsGogs Vulnerable to 2FA Bypass via Recovery Code

Risk 79
Severity
8.8
First published (updated )

Gogs GogsGogs's update .git/config file allows remote command execution

Risk 86
Severity
9.8
First published (updated )

oss-secCVE-2025-8110 in Gogs self-hosted git service

First published (updated )

oss-secCVE-2025-8110 in Gogs self-hosted git service

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

The RegisterFederal agencies told to fix or ditch Gogs as exploited zero-day lands on CISA hit list

First published (updated )

BleepingComputerCISA orders feds to patch Gogs RCE flaw exploited in zero-day attacks

First published (updated )

oss-secCVE-2025-8110 in Gogs self-hosted git service

BleepingComputerHackers exploit unpatched Gogs zero-day to breach 700 servers

First published (updated )

The Register700+ self-hosted Gits battered in 0-day attacks with no fix imminent

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Gogs GogsGogs Path Traversal Vulnerability

Risk 95
Severity
8.8
First published (updated )

Gogs GogsGogs stored XSS in PDF renderer

Risk 43
Severity
6.3
First published (updated )

Gogs GogsGogs deletion of internal files allows remote command execution

Risk 87
Severity
10
First published (updated )

go/gogs.io/gogsGogs has a Path Traversal in file update API

Risk 85
Severity
8.8
First published (updated )

go/gogs.io/gogsGogs has a Path Traversal in file editing UI

Risk 86
Severity
9.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203