repo

package

Versions in this module

v1
Mar 19, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 2, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 5, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 16, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 6, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 9, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 16, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 11, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 23, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 20, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2020 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 7, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 23, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 21, 2021 GO-2022-0353 +20 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 7, 2021 GO-2022-0353 +20 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 4, 2021 GO-2022-0353 +21 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 1, 2021 GO-2022-0353 +21 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 28, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 2, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 10, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 17, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 16, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 1, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 3, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 28, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 11, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 21, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 8, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 18, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 8, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 21, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 30, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 9, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 1, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 10, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 6, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 16, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 10, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 22, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 8, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 10, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 6, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 16, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 17, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
type Branch
Jan 2, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 5, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 30, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 6, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 13, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 30, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 8, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 7, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 22, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 31, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 15, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 6, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 19, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 17, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 29, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 8, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 20, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 13, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 27, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 19, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 13, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 27, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 13, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 27, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 15, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 31, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 22, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 18, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 4, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 3, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 3, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 16, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 4, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 21, 2018 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 9, 2018 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 23, 2018 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 4, 2018 GO-2022-0310 +25 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 17, 2018 GO-2022-0310 +25 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 17, 2018 GO-2022-0310 +25 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 31, 2018 GO-2022-0310 +25 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 9, 2018 GO-2022-0310 +25 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 3, 2018 GO-2022-0310 +26 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 10, 2018 GO-2022-0310 +26 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 21, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 3, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 3, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 26, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 4, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 3, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 25, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 16, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 2, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 1, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 19, 2018 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 14, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 9, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 29, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 27, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 15, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 3, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 26, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 16, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 12, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 23, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 6, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 25, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 4, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 6, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 29, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 4, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 9, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 21, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 5, 2017 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 23, 2016 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
v0
Oct 17, 2016 GO-2022-0310 +27 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0315: Reuse of one time passwords allowed in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-0844: Gitea Remote Code Execution (RCE) in code.gitea.io/gitea
Alert  GO-2022-0982: Improper Privilege Management in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1922: Gitea XSS Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL