Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gocd — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in gocd, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerabilities for the GoCD product, categorized by weakness type and vendor advisory tags. It collects known security flaws in GoCD, including authentication bypasses, input validation errors, and access control defects, covering advisories published over the product's active support lifecycle. Readers can use this page to track the vendor's recent security updates, understand recurring weakness classes, and review the product's historical vulnerability pattern. The entries are organized by severity and date, allowing for quick assessment of exposure. No specific CVE IDs are listed here; the focus is on categorization and trend analysis rather than individual incident details.

Vendor: n/a

CVE ID Title CVSS Severity Published
CVE-2026-55632 GoCD is vulnerable to authorization bypass via pipeline structure API CWE-863 4.3 Medium 2026-09-23
CVE-2026-52744 GoCD is vulnerable to authorization bypass via fetch artifact autosuggestion API CWE-862 5.3 Medium 2026-09-23
CVE-2026-52742 GoCD is vulnerable to historical server configuration API authorization bypass CWE-863 5.1 Medium 2026-09-21
CVE-2026-55870 GoCD is vulnerable to credential exposure when admins insecurely configure material URLs CWE-200 2.3 Low 2026-09-21
CVE-2026-55625 GoCD is vulnerable to authorization bypass via material connection test APIs CWE-639 4.9 Medium 2026-09-21
CVE-2026-52740 GoCD is vulnerable to pipeline template view API authorization bypass CWE-863 5.3 Medium 2026-09-21
CVE-2026-55060 GoCD is vulnerable to authorization bypass via support process list API CWE-863 3.7 Low 2026-09-21
CVE-2026-52741 GoCD has stored XSS possible via tracking tool link highlighting on Compare Pipeline pages CWE-80 7.5 High 2026-09-21
CVE-2026-68919 GoCD has stored XSS possible via forged package material comments on Stage/Job/VSM pages CWE-80 7.0 High 2026-09-21
CVE-2026-52743 GoCD before 26.1.0 is vulnerable to authorization bypass via job status API CWE-639 4.3 Medium 2026-09-21
CVE-2024-56324 GoCD vulnerable to XXE injection via abuse of pipeline XML "snippet" editing by group admins CWE-611 6.5 - 2025-01-03
CVE-2024-56322 GoCD vulnerable to XXE injection via abuse of unused XML configuration repository functionality CWE-611 6.7 - 2025-01-03
CVE-2024-56321 GoCD can allow malicious GoCD admins to abuse backup configuration to gain additional host access CWE-20 3.8 Low 2025-01-03
CVE-2024-56320 GoCD vulnerable to admin privilege escalation by a malicious internal/existing authenticated user CWE-285 8.8 - 2025-01-03
CVE-2024-28866 GoCD vulnerable to reflected Cross-site Scripting possible on server loading page during start-up CWE-79 3.1 Low 2024-05-13
CVE-2023-28629 Stored XSS possible on VSM and Job Details pages via malicious pipeline label configuration in gocd CWE-79 5.4 Medium 2023-03-27
CVE-2023-28630 Sensitive information disclosure possible on misconfigured failed backups of non-H2 databases in gocd CWE-532 4.2 Medium 2023-03-27
CVE-2022-39311 Compromised agents may be able to execute remote code on GoCD Server CWE-502 9.1 Critical 2022-10-14
CVE-2022-39310 Malicious agent may be able to impersonate another agent in GoCD CWE-284 4.9 Medium 2022-10-14
CVE-2022-39309 GoCD server secret encryption/decryption key leaked to agents during material serialization CWE-200 4.9 Medium 2022-10-14
CVE-2022-39308 GoCD API authentication of user access tokens subject to timing attack during comparison CWE-208 6.5 Medium 2022-10-14
CVE-2022-36088 GoCD Windows installations outside default location inadequately restrict installation file permissions CWE-284 5.0 Medium 2022-09-07
CVE-2022-29184 Command Injection/Argument Injection in GoCD CWE-77 8.8 High 2022-05-20
CVE-2022-29183 Reflected XSS in GoCD CWE-79 4.3 Medium 2022-05-20
CVE-2022-29182 DOM-based XSS in GoCD CWE-79 4.3 Medium 2022-05-20
CVE-2022-24832 Bundled ldap-authentication-plugin fails to neutralise LDAP special elements in usernames CWE-74 8.2 High 2022-04-11
CVE-2021-25924 Aravind SV gocd 跨站请求伪造漏洞 8.8 - 2021-04-01

All 27 known CVE vulnerabilities affecting gocd with full Chinese analysis, references, and POCs where available.