CVE-2026-52797Gogs: Overwriting critical files results in a denial of service Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52813Gogs: Path Traversal in organization name results in RCE through Git hooks Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Critical CVE-2026-52812Gogs: LFS dedupe path leaks private repo content across tenants Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52811Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym Exploitation status Not known exploited Fix YesAffected product G gogs Published 06/24/2026 Severity Critical CVE-2026-52810Gogs: Write to readonly repositories using receive-pack + service=git-upload-pack confusion Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52809Gogs: Password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52808Gogs: Write-level collaborators can mutate admin-only repository settings via API Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52816Gogs: Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52807Gogs: DOM-based XSS via Milestone Name on New Issue Page Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52805Gogs: Migration Redirect Bypass Leads to Internal Repository Theft Exploitation status Not known exploited Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52806Gogs: RCE via git rebase --exec argument injection in pull request merge Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Critical CVE-2026-52804Gogs: Privilege Escalation via Collaboration Access Mode Validation Exploitation status Not known exploited Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52799Gogs: Missing Authorization in Attachment Download Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52801Gogs: Ability to import local repositories via Mirror Settings Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52800Gogs: CSRF Leading to Organization Owner Takeover Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52802Gogs: Open Redirect via redirect_to in Gogs Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52814Gogs: Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52798Gogs: Stored XSS in `.ipynb` Preview Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52796Gogs: DoS in rendering issue index pattern Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Low CVE-2026-47267Gogs: SSRF in webhook deliveries Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-25119Gogs: Authentication Bypass via Unvalidated Reverse Proxy Headers Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity High CVE-2026-52795Gogs: Authorization Bypass in Watch API allows any user to monitor private repository activity Exploitation status Public exploit Fix Not confirmed Affected product G gogs Published 06/24/2026 Severity Medium CVE-2025-64719Gogs: Denial of Service in repository/wiki file listing web pages Exploitation status Not known exploited Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-52815Gogs: Unauthenticated Organization Teams Information Disclosure via API Exploitation status Public exploit Fix YesAffected product G gogs Published 06/24/2026 Severity Medium CVE-2026-26276Gogs: DOM-based XSS via milestone selection Exploitation status Not known exploited Fix YesAffected product G gogs Published 03/05/2026 Severity High CVE-2026-26196Gogs: Access tokens get exposed through URL params in API requests Exploitation status Not known exploited Fix YesAffected product G gogs Published 03/05/2026 Severity Medium CVE-2026-26195Gogs: Stored XSS in branch and wiki views through author and committer names Exploitation status Not known exploited Fix YesAffected product G gogs Published 03/05/2026 Severity Medium CVE-2026-26194Gogs: Release tag option injection in release deletion Exploitation status Not known exploited Fix YesAffected product G gogs Published 03/05/2026 Severity High CVE-2026-25921Gogs: Cross-repository LFS object overwrite via missing content hash verification Exploitation status Public exploit Fix YesAffected product G gogs Published 03/05/2026 Severity Critical CVE-2026-26022Gogs: Stored XSS via data URI in issue comments Exploitation status Public exploit Fix YesAffected product G gogs Published 03/05/2026 Severity High CVE-2026-25229Gogs Authorization Bypass Allows Cross-Repository Label Modification Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/19/2026 Severity Medium CVE-2026-25242Gogs allows unauthenticated file uploads Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/19/2026 Severity Medium CVE-2026-25232Gogs has a Protected Branch Deletion Bypass in Web Interface Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/19/2026 Severity High CVE-2026-25120Gogs Allows Cross-Repository Comment Deletion via DeleteComment Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/19/2026 Severity Medium CVE-2026-24135Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update Exploitation status Public exploit Fix YesAffected product G gogs Published 02/06/2026 Severity High CVE-2026-23633Gogs has arbitrary file read/write via path traversal in Git hook editing Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/06/2026 Severity Medium CVE-2026-23632Gogs user can update repository content with read-only permission Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/06/2026 Severity Medium CVE-2026-22592Gogs is Vulnerable to Denial of Service Exploitation status Public exploit Fix YesAffected product G gogs Published 02/06/2026 Severity Medium CVE-2025-64175Gogs Vulnerable to 2FA Bypass via Recovery Code Exploitation status Not known exploited Fix YesAffected product G gogs Published 02/06/2026 Severity High CVE-2025-64111Gogs's update .git/config file allows remote command execution Exploitation status Public exploit Fix YesAffected product G gogs Published 02/06/2026 Severity Critical CVE-2025-8110File overwrite in file update API in Gogs Exploitation status KEV Fix YesAffected product G gogs Published 12/10/2025 Severity High CVE-2025-47943Gogs stored XSS in PDF renderer Exploitation status Public exploit Fix Not confirmed Affected product G gogs Published 06/24/2025 Severity Medium CVE-2024-56731Gogs deletion of internal files allows remote command execution Exploitation status Not known exploited Fix YesAffected product G gogs Published 06/24/2025 Severity Critical CVE-2024-55947Gogs has a Path Traversal in file update API Exploitation status Public exploit Fix YesAffected product G gogs Published 12/23/2024 Severity High CVE-2024-54148Gogs has a Path Traversal in file editing UI Exploitation status Public exploit Fix YesAffected product G gogs Published 12/23/2024 Severity High CVE-2022-1884Remote Command Execution in gogs/gogs Exploitation status Public exploit Fix Not confirmed Affected product G gogs/gogs Published 11/15/2024 Severity Critical CVE-2024-44625Exploitation status Public exploit Fix Not confirmed Affected product Not confirmed Published 11/15/2024 Severity High CVE-2024-39930Exploitation status Public exploit Fix Not confirmed Affected product Not confirmed Published 07/04/2024 Severity Critical CVE-2024-39933Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 07/04/2024 Severity High CVE-2024-39931Exploitation status Not known exploited Fix Not confirmed Affected product Not confirmed Published 07/04/2024 Severity Critical CVE-2024-39932Exploitation status Public exploit Fix Not confirmed Affected product Not confirmed Published 07/04/2024 Severity Critical CVE-2022-2024OS Command Injection in gogs/gogs Exploitation status Public exploit Fix YesAffected product G gogs/gogs Published 02/25/2023 Severity Critical CVE-2022-32174Gogs - XSS Exploitation status Public exploit Fix Not confirmed Affected product G gogs Published 10/11/2022 Severity Critical CVE-2022-1986OS Command Injection in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 06/09/2022 Severity Critical CVE-2022-31038XSS vulnerability in repository issue list in Gogs Exploitation status Not known exploited Fix YesAffected product G gogs Published 06/08/2022 Severity Medium CVE-2022-1993Path Traversal in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 06/08/2022 Severity High CVE-2022-1992Path Traversal in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 06/08/2022 Severity Critical CVE-2022-1285Server-Side Request Forgery (SSRF) in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 06/01/2022 Severity High CVE-2021-32546Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 05/31/2022 Severity Unknown CVE-2022-1464Stored xss bug in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 05/05/2022 Severity High CVE-2022-0415Remote Command Execution in uploading repository file in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 03/21/2022 Severity Critical CVE-2022-0870Server-Side Request Forgery (SSRF) in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 03/11/2022 Severity Medium CVE-2022-0871Missing Authorization in gogs/gogs Exploitation status Not confirmed Fix YesAffected product G gogs/gogs Published 03/11/2022 Severity High CVE-2020-15867Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 10/16/2020 Severity Unknown CVE-2020-14958Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 06/21/2020 Severity Unknown CVE-2020-9329Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 02/21/2020 Severity Unknown CVE-2019-14544Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 08/02/2019 Severity Unknown CVE-2018-20303Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 12/20/2018 Severity Unknown CVE-2018-18925Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 11/04/2018 Severity Unknown CVE-2018-17031Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 09/14/2018 Severity Unknown CVE-2018-16409Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 09/03/2018 Severity Unknown CVE-2018-15192Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 08/08/2018 Severity Unknown CVE-2018-15193Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 08/08/2018 Severity Unknown CVE-2018-15178Exploitation status Not confirmed Fix Not confirmed Affected product Not confirmed Published 08/08/2018 Severity Unknown