Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

gogs — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in gogs, with AI-generated Chinese analysis, references, and POCs.

This page aggregates security vulnerabilities affecting the Gogs product, focusing on its software weaknesses and associated advisories. It collects known issues spanning recent years, covering both high-severity flaws and lower-risk configuration problems. Readers can track the vendor's advisory history, understand specific weakness classes, and review the product's cumulative vulnerability landscape without parsing individual CVE records separately.

Vendor: gogs

CVE ID Title CVSS Severity Published
CVE-2026-25229 Gogs Authorization Bypass Allows Cross-Repository Label Modification CWE-284 4.3 - 2026-02-19
CVE-2026-25242 Gogs allows unauthenticated file uploads CWE-862 9.8 - 2026-02-19
CVE-2026-25232 Gogs has a Protected Branch Deletion Bypass in Web Interface CWE-863 8.8 - 2026-02-19
CVE-2026-25120 Gogs Allows Cross-Repository Comment Deletion via DeleteComment CWE-639 4.9 - 2026-02-19
CVE-2026-24135 Gogs vulnerable to arbitrary file deletion via path traversal in wiki page update CWE-22 8.1AI High AI 2026-02-06
CVE-2026-23633 Gogs has arbitrary file read/write via path traversal in Git hook editing CWE-22 6.5 Medium 2026-02-06
CVE-2026-23632 Gogs user can update repository content with read-only permission CWE-862 6.5 Medium 2026-02-06
CVE-2026-22592 Gogs is Vulnerable to Denial of Service CWE-862 6.5 Medium 2026-02-06
CVE-2025-64175 Gogs Vulnerable to 2FA Bypass via Recovery Code CWE-287 8.2AI High AI 2026-02-06
CVE-2025-64111 Gogs's update .git/config file allows remote command execution CWE-78 8.8AI High AI 2026-02-06
CVE-2025-8110 File overwrite in file update API in Gogs CWE-22 7.8AI High AI 2025-12-10
CVE-2025-47943 Gogs stored XSS in PDF renderer CWE-79 6.3 Medium 2025-06-24
CVE-2024-56731 Gogs deletion of internal files allows remote command execution CWE-552 10.0 Critical 2025-06-24
CVE-2024-55947 Gogs has a Path Traversal in file update API CWE-22 8.8 - 2024-12-23
CVE-2024-54148 Gogs has a Path Traversal in file editing UI CWE-61 8.8 - 2024-12-23
CVE-2022-32174 Gogs - XSS CWE-79 7.6 - 2022-10-11
CVE-2022-31038 XSS vulnerability in repository issue list in Gogs CWE-79 5.4 Medium 2022-06-08

All 47 known CVE vulnerabilities affecting gogs with full Chinese analysis, references, and POCs where available.