git

package

Versions in this module

v1
Sep 24, 2025 GO-2025-4261
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Dec 18, 2025 GO-2025-4261
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Nov 22, 2025 GO-2025-4261
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Nov 4, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Oct 29, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Sep 25, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Apr 28, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Oct 25, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Sep 11, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Aug 13, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Aug 4, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Jul 15, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Jun 20, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Jun 19, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Jun 10, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Changes in this version
type Features
type GrepOptions
Apr 29, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Dec 16, 2024 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
May 12, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Apr 7, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Mar 24, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Mar 4, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Feb 19, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Feb 6, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Feb 5, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Jan 10, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Jan 9, 2025 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Dec 17, 2024 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Mar 28, 2024 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Dec 13, 2024 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Dec 11, 2024 GO-2025-4258 +1 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Nov 25, 2024 GO-2025-4258 +2 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Oct 9, 2024 GO-2025-4258 +2 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Sep 5, 2024 GO-2025-4258 +3 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 4, 2024 GO-2025-4258 +5 more
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 27, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Apr 27, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 28, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 20, 2023 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 16, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 25, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 22, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 13, 2024 GO-2024-3056 +6 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 26, 2024 GO-2024-3056 +7 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 22, 2024 GO-2024-3056 +7 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 1, 2024 GO-2024-3056 +7 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 17, 2024 GO-2024-3056 +7 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 21, 2023 GO-2024-3056 +7 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 12, 2023 GO-2024-3056 +7 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Nov 26, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 14, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 19, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 6, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 20, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 7, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 26, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 3, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 8, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 20, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 29, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 22, 2023 GO-2024-3056 +8 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 16, 2023 GO-2024-3056 +9 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 24, 2023 GO-2024-3056 +9 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 23, 2023 GO-2024-3056 +9 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 7, 2023 GO-2024-3056 +9 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 22, 2023 GO-2024-3056 +9 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 4, 2023 GO-2024-3056 +9 more
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 3, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 27, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 13, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 20, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 5, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 22, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 26, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 21, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 20, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 23, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 19, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 17, 2023 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 29, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Nov 24, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 25, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 21, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 15, 2022 GO-2023-1894 +10 more
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 6, 2022 GO-2022-1065 +11 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 18, 2022 GO-2022-1065 +12 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
type RunOpts
Jul 30, 2022 GO-2022-1065 +12 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Jul 19, 2022 GO-2022-1065 +12 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 20, 2022 GO-2022-1065 +12 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 19, 2022 GO-2022-1065 +12 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 21, 2022 GO-2022-1065 +12 more
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 16, 2022 GO-2022-0612 +14 more
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 2, 2022 GO-2022-0612 +14 more
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 20, 2022 GO-2022-0450 +15 more
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 24, 2022 GO-2022-0450 +15 more
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
type CloneRepoOptions
Mar 14, 2022 GO-2022-0450 +16 more
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 3, 2022 GO-2022-0442 +18 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 24, 2022 GO-2022-0442 +18 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 6, 2022 GO-2022-0442 +18 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 30, 2022 GO-2022-0442 +18 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
type ArchiveType
type CheckAttributeOpts
type CloneRepoOptions
Jan 19, 2022 GO-2022-0442 +18 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 15, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 30, 2022 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 14, 2022 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 30, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 21, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 2, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 28, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 21, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 8, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 20, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 3, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 2, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 22, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Aug 6, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 22, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 15, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 19, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 2, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 5, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 16, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 6, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 9, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Apr 16, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 11, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Mar 23, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 20, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2020 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 7, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 23, 2021 GO-2022-0442 +19 more
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 21, 2021 GO-2022-0353 +20 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 7, 2021 GO-2022-0353 +20 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 4, 2021 GO-2022-0353 +21 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 1, 2021 GO-2022-0353 +21 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 28, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 2, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 10, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 17, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 16, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 1, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 3, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 28, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 11, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 21, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2020 GO-2022-0353 +22 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Jun 8, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 18, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 8, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 21, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jun 18, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 30, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
May 9, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Apr 1, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 10, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 6, 2020 GO-2022-0353 +23 more
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 16, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 10, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
type CloneRepoOptions
type CommitTreeOpts
Jan 22, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 8, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 10, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Mar 6, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Feb 16, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 17, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jan 2, 2020 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Dec 5, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 30, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 6, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Nov 13, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 30, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Oct 8, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Sep 7, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 22, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Aug 14, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 31, 2019 GO-2022-0310 +24 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2757: Buffer Overflow in gitea in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Changes in this version
Jul 15, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea
Jul 6, 2019 GO-2022-0310 +23 more
Alert  GO-2022-0310: Capture-replay in Gitea in code.gitea.io/gitea
Alert  GO-2022-0353: Path Traversal in Gitea in code.gitea.io/gitea
Alert  GO-2022-0442: Arbitrary file deletion in gitea in code.gitea.io/gitea
Alert  GO-2022-0450: Shell command injection in gitea in code.gitea.io/gitea
Alert  GO-2022-0609: Gitea Missing Authorization vulnerability in code.gitea.io/gitea
Alert  GO-2022-0612: Stored Cross-site Scripting in gitea in code.gitea.io/gitea
Alert  GO-2022-0830: Denial of Service in Gitea in code.gitea.io/gitea
Alert  GO-2022-0832: Cross-site Scripting in Gitea in code.gitea.io/gitea
Alert  GO-2022-1065: Gitea vulnerable to Argument Injection in code.gitea.io/gitea
Alert  GO-2023-1894: code.gitea.io/gitea Open Redirect vulnerability
Alert  GO-2023-1971: Gogs and Gitea SSRF Vulnerability in code.gitea.io/gitea
Alert  GO-2023-1999: Gitea erroneous repo clones in code.gitea.io/gitea
Alert  GO-2024-2752: Gitea Open Redirect in code.gitea.io/gitea
Alert  GO-2024-2769: Gitea allowed assignment of private issues in code.gitea.io/gitea
Alert  GO-2024-3056: Gitea Cross-site Scripting Vulnerability in code.gitea.io/gitea
Alert  GO-2025-4258: Gitea mishandles authorization for deletion of releases in code.gitea.io/gitea
Alert  GO-2025-4261: Gitea allows attackers to add attachments with forbidden file extensions in code.gitea.io/gitea
Alert  GO-2025-4262: Gitea: anonymous user can visit private user's project in code.gitea.io/gitea
Alert  GO-2025-4263: Gitea allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text in code.gitea.io/gitea
Alert  GO-2025-4264: Gitea sometimes mishandles propagation of token scope for access control within one of its own package registries in code.gitea.io/gitea
Alert  GO-2025-4265: Gitea vulnerable to Cross-site Scripting in code.gitea.io/gitea
Alert  GO-2025-4266: Gitea inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order in code.gitea.io/gitea
Alert  GO-2025-4267: Gitea doesn't adequately enforce branch deletion permissions after merging a pull request. in code.gitea.io/gitea
Alert  GO-2025-4268: Gitea mishandles access to a private resource upon receiving an API token with scope limited to public resources in code.gitea.io/gitea

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL