CVE Tools

Gforge

17 CVEs tracked since 2005. Since Aug 2005, none of them reached CISA KEV.

Gforge CVEs per month

Aug 2005 to Dec 2009. Point at a month, or focus the strip and use the arrow keys.
Gforge CVEs per month, with the share now in CISA KEV
MonthCVEsIn CISA KEV
2005-0820
2005-09null or fewer
2005-10null or fewer
2005-11null or fewer
2005-12null or fewer
2006-01null or fewer
2006-02null or fewer
2006-03null or fewer
2006-04null or fewer
2006-0510
2006-06null or fewer
2006-07null or fewer
2006-08null or fewer
2006-09null or fewer
2006-10null or fewer
2006-11null or fewer
2006-12null or fewer
2007-01null or fewer
2007-02null or fewer
2007-03null or fewer
2007-04null or fewer
2007-0510
2007-06null or fewer
2007-07null or fewer
2007-08null or fewer
2007-0920
2007-10null or fewer
2007-1110
2007-12null or fewer
2008-0110
2008-02null or fewer
2008-03null or fewer
2008-04null or fewer
2008-0510
2008-06null or fewer
2008-07null or fewer
2008-08null or fewer
2008-09null or fewer
2008-10null or fewer
2008-11null or fewer
2008-12null or fewer
2009-0110
2009-0230
2009-03null or fewer
2009-04null or fewer
2009-05null or fewer
2009-06null or fewer
2009-07null or fewer
2009-08null or fewer
2009-09null or fewer
2009-10null or fewer
2009-1130
2009-1210

Products

The products that kept showing up in Gforge's monthly top three, with their CVEs summed over those months.

  1. Gforge1711 months

Latest CVEs

The 15 most recently published vulnerabilities affecting Gforge.

  1. CVE-2019-10016GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.6.1
  2. CVE-2009-3304GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.p...3.3
  3. CVE-2009-3303Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.4.3
  4. CVE-2009-4070SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.7.5
  5. CVE-2009-4069Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.4.3
  6. CVE-2008-6187SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter.7.5
  7. CVE-2008-6188SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter.7.5
  8. CVE-2008-6189SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) top/topusers.php, w...7.5
  9. CVE-2008-2381SQL injection vulnerability in the create function in common/include/GroupJoinRequest.class in GForge 4.5 and 4.6 allows remote attackers to execute arbitrary SQL commands via the comments variable.7.5
  10. CVE-2008-0167The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attackers to bypass int...4.6
  11. CVE-2008-0173SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports.7.5
  12. CVE-2007-3921gforge 3.1 and 4.5.14 allows local users to truncate arbitrary files via a symlink attack on temporary files.3.3
  13. CVE-2007-3918Cross-site scripting (XSS) vulnerability in account/verify.php in GForge 4.6b2 allows remote attackers to inject arbitrary web script or HTML via the confirm_hash parameter.4.3
  14. CVE-2007-4966SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter.6.8
  15. CVE-2007-3913SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.7.5

The record

Peak rank
#28 in Nov 2009
Busiest month shown
Feb 2009, 3 CVEs
Months with a KEV entry
0 since Aug 2005
Monthly snapshots
11 since 2005
Gforge's full record, month by month

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store