Forceu develops Gokapi, a niche file-sharing and upload-management application whose vulnerability profile centers on application-layer security gaps including access-control weaknesses, cross-site scripting variants, CSRF, and resource-exhaustion conditions typical of web services handling user input and session state. The recurring weakness classes reflect the core challenges of securing file-handling workflows and user interactions in web applications. Current severity, exploitation, and CVE counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forceu over time
Signals from CVEs in this vendor scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-28683HIGH Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads SVG and creates a ho | Mar 6, 2026 | 8.7 | 30 | NO | NO |
CVE-2026-28682MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishe | Mar 6, 2026 | 6.4 | 23 | NO | NO |
CVE-2026-30955MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limi | Mar 13, 2026 | 6.5 | 22 | NO | NO |
CVE-2026-29061MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user rank demotion | Mar 6, 2026 | 5.4 | 21 | NO | NO |
CVE-2026-30961MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate | Mar 13, 2026 | 4.3 | 17 | NO | NO |
CVE-2026-30943MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a u | Mar 13, 2026 | 4.1 | 17 | NO | NO |
CVE-2026-29084MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the login flow accepts credential-bearing requests without CSR | Mar 6, 2026 | 4.6 | 17 | NO | NO |
CVE-2026-29060MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file | Mar 6, 2026 | 5.0 | 17 | NO | NO |
CVE-2025-48495MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly name of an API key, an authenticated user could inject JS int | Jun 2, 2025 | 5.4 | 17 | NO | NO |
CVE-2025-48494MEDIUM Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encryption, a stored cross-site scripting vulnerability can be e | Jun 2, 2025 | 5.4 | 17 | NO | NO |
Signals from CVEs in this vendor scope (10 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forceu.
Media articles that mention a CVE ID that affects a product developed by Forceu — matched by CVE ID, not by vendor name.