VYPR

Gitea

by Go Gitea

Source repositories

CVEs (146)

  • CVE-2026-58510MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    GHSA-8fwc-qjw5-rvgp ClearRepoWatches fix not applied to API EditRepo path — sister code path retains stale watches on public->private

  • CVE-2026-58431MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    Public-only API token restriction is not enforced on team API routes

  • CVE-2026-55986MedAug 13, 2026
    risk 0.28cvss 5.4epss 0.00

    Email Management API Bypasses ManageCredentials Feature Restrictions

  • CVE-2026-50105MedAug 13, 2026
    risk 0.28cvss 4.3epss 0.00

    RSS/Atom feed handlers bypass API-token scope & public-only confinement (incomplete fix of #37698)

  • CVE-2025-68946MedDec 26, 2025
    risk 0.28cvss 5.4epss 0.00

    In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.

  • CVE-2025-68942MedDec 26, 2025
    risk 0.28cvss 5.4epss 0.00

    Gitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.

  • CVE-2022-1928MedMay 29, 2022
    risk 0.28cvss 5.4epss 0.01

    Cross-site Scripting (XSS) - Stored in GitHub repository go-gitea/gitea prior to 1.16.9.

  • CVE-2018-1000803MedOct 8, 2018
    risk 0.28cvss 5.3epss 0.01

    Gitea version prior to version 1.5.1 contains a CWE-200 vulnerability that can result in Exposure of users private email addresses. This attack appear to be exploitable via Watch a repository to receive email notifications. Emails received contain the other recipients even if…

  • CVE-2026-58507MedAug 13, 2026
    risk 0.27cvss 5.3epss 0.00

    Private Repository Existence Disclosure via go-get Meta Endpoint

  • CVE-2025-69413MedJan 1, 2026
    risk 0.27cvss 5.3epss 0.00

    In Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.

  • CVE-2025-68943MedDec 26, 2025
    risk 0.27cvss 5.3epss 0.00

    Gitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.

  • CVE-2026-59766medJul 21, 2026
    risk 0.26cvss epss

    ## Summary CVE-2026-20800 fixed private-info leakage to revoked users only for the notification endpoint. Two sibling endpoints that return data keyed on the caller's own relationship still do not re-check repo access at output time: - `GET /api/v1/user/starred` —…

  • CVE-2025-68944MedDec 26, 2025
    risk 0.26cvss 5.0epss 0.00

    Gitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.

  • CVE-2026-58429MedAug 13, 2026
    risk 0.25cvss 4.9epss 0.00

    Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

  • CVE-2025-68941MedDec 26, 2025
    risk 0.25cvss 4.9epss 0.00

    Gitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.

  • CVE-2026-52807MedJun 24, 2026
    risk 0.24cvss epss 0.00

    Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevents direct HTML injection. However, when the browser renders the DOM, the text…

  • CVE-2023-3515MedJul 5, 2023
    risk 0.22cvss 4.4epss 0.00

    Open Redirect in GitHub repository go-gitea/gitea prior to 1.19.4.

  • CVE-2026-59763MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Unbounded Arch package file metadata can cause resource amplification in Gitea package uploads

  • CVE-2026-58444MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    Personal access token scope enforcement bypass on the repository home page (`GET /{owner}/{repo}`) discloses private repository contents

  • CVE-2026-58425MedAug 13, 2026
    risk 0.21cvss 4.3epss 0.00

    OAuth token introspection returns metadata of tokens issued to other clients (RFC 7662 section 4 violation)

Page 5 of 8