Gforge provides collaboration and project-management platforms that serve as centralized repositories for software development teams, spanning products such as Gforge, Advanced Server, and Garennes. The vendor's vulnerability footprint, though modest in volume, occupies a more prominent position in the landscape than its product count alone suggests, reflecting the critical role these platforms play in managing access to code and project artifacts. Vulnerabilities concentrate in application-layer input-handling and server-side logic: SQL injection, cross-site scripting, link-resolution flaws, and improper input validation recur across the product line, consistent with the challenges of building web-facing collaboration interfaces that parse user input and generate dynamic content. Public exploit code for these flaws has frequently become available, making timely patching essential for organizations running exposed instances. Current exploitation activity, severity distribution, and detailed exposure metrics are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gforge over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2008-6189HIGH SQL injection vulnerability in GForge 4.5.19 allows remote attackers to execute arbitrary SQL commands via the offset parameter to (1) new/index.php, (2) news/index.php, and (3) to | Feb 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6188HIGH SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_edit[] parameter. | Feb 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2008-6187HIGH SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitrary SQL commands via the release_id parameter. | Feb 19, 2009 | 7.5 | 28 | NO | YES |
CVE-2007-3913HIGH SQL injection vulnerability in Gforge before 3.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | Sep 6, 2007 | 7.5 | 28 | NO | YES |
CVE-2007-2298HIGH Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertoire_config parameter t | Apr 26, 2007 | 7.5 | 28 | NO | YES |
CVE-2005-1752MEDIUM viewFile.php in the scm component of Gforge before 4.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file_name parameter. | Dec 31, 2005 | 6.4 | 27 | NO | YES |
CVE-2007-4966MEDIUM SQL injection vulnerability in www/people/editprofile.php in GForge 4.6b2 and earlier allows remote attackers to execute arbitrary SQL commands via the skill_delete[] parameter. | Sep 18, 2007 | 6.8 | 26 | NO | YES |
CVE-2008-0167MEDIUM The write_array_file function in utils/include.pl in GForge 4.5.14 updates configuration files by truncating them to zero length and then writing new data, which might allow attack | May 18, 2008 | 4.6 | 25 | NO | YES |
CVE-2008-0173HIGH SQL injection vulnerability in Gforge 4.6.99 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified parameters, related to RSS exports. | Jan 15, 2008 | 7.5 | 23 | NO | NO |
CVE-2019-10016MEDIUM GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring. | Mar 25, 2019 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gforge.
Media articles that mention a CVE ID that affects a product developed by Gforge — matched by CVE ID, not by vendor name.