GO-2022-1060: Gogs vulnerable to Cross-site Scripting in gogs.io/gogs
GO-2024-3275: Unpatched Remote Code Execution in Gogs in gogs.io/gogs
GO-2025-4225: Gogs vulnerable to a bypass of CVE-2024-55947 in gogs.io/gogs
GO-2026-4448: Gogs's update .git/config file allows remote command execution in gogs.io/gogs
GO-2026-4449: Gogs Vulnerable to 2FA Bypass via Recovery Code in gogs.io/gogs
GO-2026-4450: Gogs user can update repository content with read-only permission in gogs.io/gogs
GO-2026-4451: Gogs has a Denial of Service issue in gogs.io/gogs
GO-2026-4452: Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update in gogs.io/gogs
GO-2026-4453: Gogs has arbitrary file read/write via Path Traversal in Git hook editing in gogs.io/gogs
GO-2026-4454: Gogs vulnerable to Stored XSS via Mermaid diagrams in gogs.io/gogs
GO-2026-4457: Gogs has authorization bypass in repository deletion API in gogs.io/gogs
GO-2026-4498: Gogs has a Protected Branch Deletion Bypass in Web Interface in gogs.io/gogs
GO-2026-4499: Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs in gogs.io/gogs
GO-2026-4500: Unauthenticated File Upload in Gogs in gogs.io/gogs
GO-2026-4501: Gogs Allows Cross-Repository Comment Deletion via DeleteComment in gogs.io/gogs
GO-2026-4616: Gogs: Cross-repository LFS object overwrite via missing content hash verification in gogs.io/gogs
GO-2026-4617: Gogs: Release tag option injection in release deletion in gogs.io/gogs
GO-2026-4618: Gogs: Stored XSS in branch and wiki views through author and committer names in gogs.io/gogs
GO-2026-4619: Gogs: Access tokens get exposed through URL params in API requests in gogs.io/gogs
GO-2026-4620: Gogs: Stored XSS via data URI in issue comments in gogs.io/gogs
GO-2026-4627: Gogs: DOM-based XSS via milestone selection in gogs.io/gogs
GO-2026-5065: Gogs's write-level collaborators can mutate admin-only repository settings via API in gogs.io/gogs
GO-2026-5098: Gogs has a Denial of Service in repository/wiki file listing web pages in gogs.io/gogs
GO-2026-5103: Gogs's Unauthenticated Jupyter Notebook (ipynb) Sanitizer allows arbitrary data: URIs leading to XSS in gogs.io/gogs
GO-2026-5110: Gogs Vulnerable to Privilege Escalation via Collaboration Access Mode Validation in gogs.io/gogs
GO-2026-5124: Gogs has DoS in rendering issue index pattern in gogs.io/gogs
GO-2026-5140: Gogs's password-reset tokens use account-activation lifetime, ignoring RESET_PASSWORD_CODE_LIVES in gogs.io/gogs
GO-2026-5184: Gogs: LFS dedupe path leaks private repo content across tenants in gogs.io/gogs
GO-2026-5193: Gogs: XSS in .ipynb files renderer due to outdated notebookjs in gogs.io/gogs
GO-2026-5202: Gogs Vulnerable to Unauthenticated Organization Teams Information Disclosure via API in gogs.io/gogs
GO-2026-5249: Gogs: UploadRepoFiles writes outside repo working tree via committed parent sym in gogs.io/gogs
GO-2026-5305: Gogs has Path Traversal in organization name that results in RCE through Git hooks in gogs.io/gogs
GO-2026-5312: Gogs has SSRF in webhook deliveries in gogs.io/gogs
GO-2026-5387: Gogs has a Migration Redirect Bypass that Leads to Internal Repository Theft in gogs.io/gogs
GO-2026-5477: Gogs has Stored XSS in `.ipynb` Preview in gogs.io/gogs
GO-2026-5536: Gogs Missing Authorization in Attachment Download in gogs.io/gogs
GO-2026-5545: Gogs: Overwriting critical files results in a denial of service in gogs.io/gogs
GO-2026-5556: Gogs Vulnerable to CSRF Leading to Organization Owner Takeover in gogs.io/gogs
GO-2026-5580: Gogs vulnerable to RCE via git rebase --exec argument injection in pull request merge in gogs.io/gogs
GO-2026-5661: Gogs has DOM-based XSS via Milestone Name on New Issue Page in gogs.io/gogs
GO-2026-5695: Gogs has an Authentication Bypass via Unvalidated Reverse Proxy Headers in gogs.io/gogs
GO-2026-5712: Gogs allows users to write to readonly repositories using receive-pack + service=git-upload-pack confusion in gogs.io/gogs
GO-2026-5724: Gogs has the ability to import local repositories via Mirror Settings in gogs.io/gogs
GO-2026-5765: Gogs has Unauthenticated Asymmetric Denial of Service (DoS) via SSH Handshake Stall (File Descriptor Exhaustion) in gogs.io/gogs
GO-2026-5773: Gogs has an Open Redirect via redirect_to in gogs.io/gogs