VYPR

Gitea

by Go Gitea

Source repositories

CVEs (147)

  • CVE-2026-58418MedJul 3, 2026
    risk 0.35cvss 6.5epss 0.00

    SSRF via HTTP Redirect in Repository Migration

  • CVE-2026-20904MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Gitea does not properly validate ownership when toggling OpenID URI visibility. An authenticated user may be able to change the visibility settings of other users' OpenID identities.

  • CVE-2026-20883MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Gitea's stopwatch API does not re-validate repository access permissions. After a user's access to a private repository is revoked, they may still view issue titles and repository names through previously started stopwatches.

  • CVE-2026-20800MedJan 22, 2026
    risk 0.35cvss 6.5epss 0.00

    Gitea's notification API does not re-validate repository access permissions when returning notification details. After a user's access to a private repository is revoked, they may still view issue and pull request titles through previously received notifications.

  • CVE-2022-38795MedAug 7, 2023
    risk 0.35cvss 6.5epss 0.01

    In Gitea through 1.17.1, repo cloning can occur in the migration function.

  • CVE-2022-38183MedAug 12, 2022
    risk 0.35cvss 6.5epss 0.01

    In Gitea before 1.16.9, it was possible for users to add existing issues to projects. Due to improper access controls, an attacker could assign any issue to any project in Gitea (there was no permission check for fetching the issue). As a result, the attacker would get access to…

  • CVE-2026-56755MedAug 13, 2026
    risk 0.33cvss 6.2epss 0.00

    Denial of Service (CPU & Memory Exhaustion) via O(N^2) String Concatenation in Debian Package Upload

  • CVE-2021-45328MedFeb 8, 2022
    risk 0.33cvss 6.1epss 0.01

    Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.

  • CVE-2019-1010314MedJul 11, 2019
    risk 0.33cvss 6.1epss 0.01

    Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable repo page is loaded. The component is: repository's description. The attack vector is: victim must navigate to public and affected repo page.

  • CVE-2026-58432MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    Missing Authorization and Authorization Bypass Through User-Controlled Key and Incorrect Permission Assignment for Critical Resource and Exposure of Sensitive Information to an Unauthorized Actor in code.gitea.io/gitea

  • CVE-2026-57886MedAug 13, 2026
    risk 0.31cvss 5.9epss 0.00

    Cross-repository issue/comment attachment re-linking can expose private attachment content

  • CVE-2025-68945MedDec 26, 2025
    risk 0.31cvss 5.8epss 0.00

    In Gitea before 1.21.2, an anonymous user can visit a private user's project.

  • CVE-2026-58420MedAug 13, 2026
    risk 0.29cvss 4.4epss 0.00

    Local File Inclusion via file:// URI in Migration Restore

  • CVE-2026-58510MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

  • CVE-2026-58431MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Public-only API token restriction is not enforced on team API routes

  • CVE-2026-55986MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Email Management API Bypasses ManageCredentials Feature Restrictions

  • CVE-2026-50105MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

  • CVE-2025-68946MedDec 26, 2025
    risk 0.28cvss 5.4epss 0.00

    In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

  • CVE-2025-68942MedDec 26, 2025
    risk 0.28cvss 5.4epss 0.00

    Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

  • CVE-2022-1928MedMay 29, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

Page 5 of 8