VYPR
Vendor

Go Gitea

Products
1
CVEs
147
Across products
147
Status
Private

Products

1

Recent CVEs

147
View all 147 CVEs →
  • CVE-2026-60004CriKEVAug 26, 2026
    risk 0.71cvss 9.8epss 0.24

    Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

  • CVE-2019-11229HigApr 15, 2019
    risk 0.65cvss 8.8epss 0.55

    models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.

  • CVE-2021-45331CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    An Authentication Bypass vulnerability exists in Gitea before 1.5.0, which could let a malicious user gain privileges. If captured, the TOTP code for the 2FA can be submitted correctly more than once.

  • CVE-2021-45330CriFeb 9, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue exsits in Gitea through 1.15.7, which could let a malicious user gain privileges due to client side cookies not being deleted and the session remains valid on the server side for reuse.

  • CVE-2020-28991CriNov 24, 2020
    risk 0.64cvss 9.8epss 0.02

    Gitea 0.9.99 through 1.12.x before 1.12.6 does not prevent a git protocol path that specifies a TCP port number and also contains newlines (with URL encoding) in ParseRemoteAddr in modules/auth/repo_form.go.

  • CVE-2019-11576CriApr 28, 2019
    risk 0.64cvss 9.8epss 0.02

    Gitea before 1.8.0 allows 1FA for user accounts that have completed 2FA enrollment. If a user's credentials are known, then an attacker could send them to the API without requiring the 2FA one-time password.

  • CVE-2025-68937CriDec 26, 2025
    risk 0.62cvss —epss 0.01

    Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.

  • CVE-2024-6886CriAug 6, 2024
    risk 0.61cvss —epss 0.33

    Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

  • CVE-2026-58508CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.00

    Two SSRF vulnerabilities in Gitea migration/mirror (DNS rebinding + missing re-validation)

  • CVE-2026-58443CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.01

    Public-only repository tokens can update private PR head branches

  • CVE-2026-58433CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.01

    Team-repository linking endpoint bypasses the RepoAdminChangeTeamAccess organization setting

  • CVE-2026-55982CriAug 13, 2026
    risk 0.59cvss 9.1epss 0.01

    OIDC userinfo Endpoint Returns Identity Claims Without Enforcing API Token Scopes

  • CVE-2026-56654CriAug 13, 2026
    risk 0.57cvss 9.8epss 0.01

    Privilege Escalation via Access Token Scope Escalation in API

  • CVE-2026-58422CriJul 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Improper authorization on OAuth sign-in callback silently re-enables administrator-disabled accounts

  • CVE-2026-28737HigJul 3, 2026
    risk 0.57cvss 8.7epss 0.00

    Gitea versions from 1.25.0 before 1.26.0 allow stored cross-site scripting through the extensionsRequired field in glTF files rendered by the 3D file viewer.

  • CVE-2026-27780CriJul 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Gitea versions before 1.26.0 do not fail closed on bufio.Scanner errors while processing pre-receive hook input, allowing oversized input to bypass branch-protection checks.

  • CVE-2026-26292CriJul 3, 2026
    risk 0.57cvss 9.8epss 0.01

    Gitea versions before 1.25.5 do not use the migration HTTP transport for LFS push and sync mirror operations, bypassing the configured migration transport protections for those LFS requests.

  • CVE-2026-20896CriJul 3, 2026
    risk 0.57cvss 9.8epss 0.03

    Gitea Docker image versions up to and including 1.26.2 use REVERSE_PROXY_TRUSTED_PROXIES=* by default, allowing any source IP to impersonate a user when reverse-proxy authentication headers such as X-WEBAUTH-USER are enabled.

  • CVE-2022-42968CriOct 16, 2022
    risk 0.57cvss 9.8epss 0.01

    Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.

  • CVE-2021-45327CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user execute arbitrary code.