Gitblit is a lightweight, self-hosted Git repository server and management platform used in decentralized development environments, with its vulnerability profile concentrated in a single product line. The durable signal centers on web-application input-handling and access-control issues, including cross-site scripting, path traversal, and improper privilege management, which reflect the challenges of securing a browser-facing Git interface. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gitblit over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-31267CRITICAL Gitblit 1.9.2 allows privilege escalation via the Config User Service: a control character can be placed in a profile data field, such as an emailAddress%3Atext '[email protected] | May 21, 2022 | 9.8 | 40 | NO | NO |
CVE-2022-31268HIGH A Path Traversal vulnerability in Gitblit 1.9.3 can lead to reading website files via /resources//../ (e.g., followed by a WEB-INF or META-INF pathname). | May 21, 2022 | 7.5 | 32 | NO | YES |
CVE-2025-50977MEDIUM A template injection vulnerability leading to reflected cross-site scripting (XSS) has been identified in version 1.7.1, requiring authenticated admin access for exploitation. The | Aug 27, 2025 | 6.1 | 21 | NO | NO |
CVE-2025-50978MEDIUM In Gitblit v1.7.1, a reflected cross-site scripting (XSS) vulnerability exists in the way repository path names are handled. By injecting a specially crafted path payload an attack | Aug 27, 2025 | 6.1 | 21 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gitblit.
Media articles that mention a CVE ID that affects a product developed by Gitblit — matched by CVE ID, not by vendor name.