VYPR
Critical severity9.0NVD Advisory· Published Oct 11, 2022· Updated Jun 17, 2026

CVE-2022-32174

CVE-2022-32174

Description

In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
gogs.io/gogsGo
>= 0.6.5, <= 0.12.10

Affected products

3
  • Gogs/Gogsv52 versions
    v0.6.5+ 1 more
    • (no CPE)range: v0.6.5
    • cpe:2.3:a:gogs:gogs:*:*:*:*:*:*:*:*range: >=0.6.5,<=0.12.10
  • ghsa-coords
    Range: >= 0.6.5, <= 0.12.10

Patches

Vulnerability mechanics

References

5

News mentions

0

No linked articles in our index yet.