CVE Tools

Gogs.io/gogs

53 CVEs tracked. 1 of them are in CISA KEV.

This hub aggregates every CVE we track for Gogs.io/gogs, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Gogs.io/gogs CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Gogs.io/gogs CVEs per month
MonthCVEs
2024-100
2024-112
2024-122
2025-010
2025-020
2025-030
2025-040
2025-050
2025-062
2025-070
2025-080
2025-090
2025-100
2025-110
2025-121
2026-010
2026-0212
2026-036
2026-040
2026-050
2026-061
2026-070
2026-080
2026-090

Severity

How the 53 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical1531%
  • High1735%
  • Medium1531%
  • Low12%

Latest CVEs

The 15 most recently published vulnerabilities affecting Gogs.io/gogs.

  1. GHSA-6vxv-wg6j-5qwpGogs: XSS in .ipynb files renderer due to outdated notebookjs—
  2. CVE-2026-26276Gogs: DOM-based XSS via milestone selection7.3
  3. CVE-2026-26196Gogs: Access tokens get exposed through URL params in API requests5.3
  4. CVE-2026-26195Gogs: Stored XSS in branch and wiki views through author and committer names6.1
  5. CVE-2026-26194Gogs: Release tag option injection in release deletion7.3
  6. CVE-2026-25921Gogs: Cross-repository LFS object overwrite via missing content hash verification9.3
  7. CVE-2026-26022Gogs: Stored XSS via data URI in issue comments8.7
  8. CVE-2026-25229Gogs Authorization Bypass Allows Cross-Repository Label Modification6.5
  9. CVE-2026-25242Gogs allows unauthenticated file uploads9.8
  10. CVE-2026-25232Gogs has a Protected Branch Deletion Bypass in Web Interface8.8
  11. CVE-2026-25120Gogs Allows Cross-Repository Comment Deletion via DeleteComment2.7
  12. CVE-2025-65852Gogs has authorization bypass in repository deletion API—
  13. GHSA-26gq-grmh-6xm6Gogs vulnerable to Stored XSS via Mermaid diagrams—
  14. CVE-2026-24135Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update8.1
  15. CVE-2026-23633Gogs has arbitrary file read/write via path traversal in Git hook editing6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store