Forgejo is a self-hosted Git service and repository platform, with vulnerabilities concentrating around its single core product and centering on access-control weaknesses including incorrect authorization logic and improper permission assignment for critical resources. These weakness patterns reflect the authentication and authorization demands of a multi-user collaborative platform; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Forgejo over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-68937CRITICAL Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for t | Dec 26, 2025 | 9.5 | 31 | NO | NO |
CVE-2026-59102MEDIUM Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by setting a | Jul 2, 2026 | 5.4 | 28 | NO | NO |
CVE-2023-49946CRITICAL In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read p | Dec 3, 2023 | 9.1 | 25 | NO | NO |
CVE-2023-49947HIGH Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication. | Dec 3, 2023 | 7.5 | 21 | NO | NO |
CVE-2023-49948MEDIUM Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL. | Dec 3, 2023 | 5.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Forgejo.
Media articles that mention a CVE ID that affects a product developed by Forgejo — matched by CVE ID, not by vendor name.