Gforge
17 CVEs tracked since 2005. Since Aug 2005, none of them reached CISA KEV.
Gforge CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2005-08 | 2 | 0 |
| 2005-09 | null or fewer | |
| 2005-10 | null or fewer | |
| 2005-11 | null or fewer | |
| 2005-12 | null or fewer | |
| 2006-01 | null or fewer | |
| 2006-02 | null or fewer | |
| 2006-03 | null or fewer | |
| 2006-04 | null or fewer | |
| 2006-05 | 1 | 0 |
| 2006-06 | null or fewer | |
| 2006-07 | null or fewer | |
| 2006-08 | null or fewer | |
| 2006-09 | null or fewer | |
| 2006-10 | null or fewer | |
| 2006-11 | null or fewer | |
| 2006-12 | null or fewer | |
| 2007-01 | null or fewer | |
| 2007-02 | null or fewer | |
| 2007-03 | null or fewer | |
| 2007-04 | null or fewer | |
| 2007-05 | 1 | 0 |
| 2007-06 | null or fewer | |
| 2007-07 | null or fewer | |
| 2007-08 | null or fewer | |
| 2007-09 | 2 | 0 |
| 2007-10 | null or fewer | |
| 2007-11 | 1 | 0 |
| 2007-12 | null or fewer | |
| 2008-01 | 1 | 0 |
| 2008-02 | null or fewer | |
| 2008-03 | null or fewer | |
| 2008-04 | null or fewer | |
| 2008-05 | 1 | 0 |
| 2008-06 | null or fewer | |
| 2008-07 | null or fewer | |
| 2008-08 | null or fewer | |
| 2008-09 | null or fewer | |
| 2008-10 | null or fewer | |
| 2008-11 | null or fewer | |
| 2008-12 | null or fewer | |
| 2009-01 | 1 | 0 |
| 2009-02 | 3 | 0 |
| 2009-03 | null or fewer | |
| 2009-04 | null or fewer | |
| 2009-05 | null or fewer | |
| 2009-06 | null or fewer | |
| 2009-07 | null or fewer | |
| 2009-08 | null or fewer | |
| 2009-09 | null or fewer | |
| 2009-10 | null or fewer | |
| 2009-11 | 3 | 0 |
| 2009-12 | 1 | 0 |
Products
The products that kept showing up in Gforge's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Gforge.
- CVE-2019-10016GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.6.1
- CVE-2009-3304GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.p...3.3
- CVE-2009-3303Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.4.3
- CVE-2009-4070SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.7.5
- CVE-2009-4069Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
- CVE-2008-6187SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.7.5
- CVE-2008-6188SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.7.5
- CVE-2008-6189SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, w...7.5
- CVE-2008-2381SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.7.5
- CVE-2008-0167The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass int...4.6
- CVE-2008-0173SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.7.5
- CVE-2007-3921gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.3.3
- CVE-2007-3918Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.4.3
- CVE-2007-4966SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.6.8
- CVE-2007-3913SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5
The record
- Peak rank
- #28 in Nov 2009
- Busiest month shown
- Feb 2009, 3 CVEs
- Months with a KEV entry
- 0 since Aug 2005
- Monthly snapshots
- 11 since 2005