gogs.io/gogs

govv0.13.3

License MITpermissive80 versions0 deps
25
/ 100
Health
do not use

gogs.io/gogs has critical vulnerabilities — do not use

Update to >= 0.13.3-0.20250608224432-110117b2e5e5 to fix known vulnerabilities

  • Low health score (25/100)
  • 8 high severity vulnerabilities
  • 2 critical vulnerabilities
Health breakdown0 – 100
10/25
maintenance
0/20
popularity
0/25
security
15/15
maturity
0/15
community
Vulnerabilities
42
2 critical8 high10 medium22 low
Advisories (42)
SeverityIDSummaryFixed in
highGO-2026-4454Gogs vulnerable to Stored XSS via Mermaid diagrams0.13.4
highCVE-2026-25232Gogs has a Protected Branch Deletion Bypass in Web Interface0.14.1
mediumCVE-2026-23632 Gogs user can update repository content with read-only permission0.13.4
criticalCVE-2026-25921Gogs: Cross-repository LFS object overwrite via missing content hash verification0.14.2
mediumCVE-2026-22592Gogs has a Denial of Service issue0.13.4
mediumCVE-2026-25229Gogs has an Authorization Bypass Allows Cross-Repository Label Modification in Gogs0.14.0
mediumCVE-2026-25242Unauthenticated File Upload in Gogs0.14.1
criticalCVE-2025-64111Gogs's update .git/config file allows remote command execution0.13.4
mediumCVE-2026-25120Gogs Allows Cross-Repository Comment Deletion via DeleteComment0.14.0
highCVE-2026-24135Gogs vulnerable to arbitrary file deletion via Path Traversal in wiki page update0.13.4
highCVE-2025-8110Gogs vulnerable to a bypass of CVE-2024-55947
mediumCVE-2026-23633Gogs has arbitrary file read/write via Path Traversal in Git hook editing0.13.4
highCVE-2025-64175Gogs Vulnerable to 2FA Bypass via Recovery Code0.13.4
mediumCVE-2025-65852Gogs has authorization bypass in repository deletion API0.13.4
highCVE-2026-26194Gogs: Release tag option injection in release deletion0.14.2
highCVE-2026-26276Gogs: DOM-based XSS via milestone selection
mediumCVE-2026-26195Gogs: Stored XSS in branch and wiki views through author and committer names
mediumCVE-2026-26196Gogs: Access tokens get exposed through URL params in API requests
mediumCVE-2025-47943Gogs XSS allowed by stored call in PDF renderer0.13.3-0.20250608224432-110117b2e5e5
highCVE-2026-26022Gogs: Stored XSS via data URI in issue comments0.14.2
... and 22 more
Threat intelligence
2 actively exploited (CISA KEV)1 likely exploited (EPSS ≥ 0.5)
Threat tier per vulnerability derived from CISA KEV catalog + FIRST.org EPSS scores.

Health History

Dependency Tree

License Audit

API access

Get this data programmatically — free, no authentication.

curl https://depscope.dev/api/check/go/gogs.io/gogs

Last updated · 2025-06-08T22:55:56Z