Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gitea Limited

First CVE: Aug 8, 2018Active for: 8 yearsTotal CVEs: 52
51.7
VTI Score
TOP TARGET

Gitea Limited maintains a self-hosted Git service platform that, despite a narrow product footprint, occupies a prominent position among development infrastructure tools and is widely deployed across organizations seeking on-premises version control. Vulnerabilities affecting Gitea skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the platform's role as a trusted authentication and repository gateway. The exposure recurs through access-control and input-validation weakness classes—including improper access control, cross-site scripting, and authorization bypass flaws—that are characteristic of web applications handling sensitive code and credentials. Defenders should prioritize Gitea advisories for internet-exposed instances and treat authentication and authorization patches as urgent, since compromised repositories can affect entire development pipelines; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
52
Total CVEs
More Total CVEs than 98% of tracked vendors
6.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
6.9
Avg CVSS Score
Higher Avg CVSS Score than 48% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Gitea Limited over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2018
7 years ago
Most Recent CVE
Jan 22, 2026
182 days ago

Self-Reporting Analysis

Of all the CVEs published by Gitea Limited as a CNA, 18.0% affect products that Gitea Limited develops as a vendor.

18.0%
82.0%
Self-reported: 9 (18.0%)
Third-party: 41 (82.0%)

Of all the CVEs published that affect products developed by Gitea Limited, 17.3% are self-published by Gitea Limited as a CNA.

17.3%
82.7%
Self-published: 9 (17.3%)
Other CNAs: 43 (82.7%)

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (52 CVEs).

52 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-14144HIGH
The git hook feature in Gitea 1.1.0 through 1.12.5 might allow for authenticated remote code execution in customer environments where the documentation was not understood (e.g., on
Oct 16, 20207.287NOYES
CVE-2022-30781HIGH
Gitea before 1.16.7 does not escape git fetch remote.
May 16, 20227.586NOYES
CVE-2019-11229HIGH
models/repo_mirror.go in Gitea before 1.7.6 and 1.8.x before 1.8-RC3 mishandles mirror repo URL settings, leading to remote code execution.
Apr 15, 20198.870NOYES
CVE-2022-1058MEDIUM
Open Redirect on login in GitHub repository go-gitea/gitea prior to 1.16.5.
Mar 24, 20226.152NOYES
CVE-2026-20912CRITICAL
Gitea does not properly validate repository ownership when linking attachments to releases. An attachment uploaded to a private repository could potentially be linked to a release
Jan 22, 20269.135NONO
CVE-2026-20897CRITICAL
Gitea does not properly validate repository ownership when deleting Git LFS locks. A user with write access to one repository may be able to delete LFS locks belonging to other rep
Jan 22, 20269.135NONO
CVE-2026-20750CRITICAL
Gitea does not properly validate project ownership in organization project operations. A user with project write access in one organization may be able to modify projects belonging
Jan 22, 20269.135NONO
CVE-2022-42968CRITICAL
Gitea before 1.17.3 does not sanitize and escape refs in the git backend. Arguments to git commands are mishandled.
Oct 16, 20229.831NONO
CVE-2021-45328MEDIUM
Gitea before 1.4.3 is affected by URL Redirection to Untrusted Site ('Open Redirect') via internal URLs.
Feb 8, 20226.131NOYES
CVE-2021-45327CRITICAL
Gitea before 1.11.2 is affected by Trusting HTTP Permission Methods on the Server Side when referencing the vulnerable admin or user API. which could let a remote malisious user ex
Feb 8, 20229.831NONO
View all 52 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products52 CVEs
54%
25%
19%
Severity distribution among all CVEs352,101 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network52 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low51 (98.1%)
High1 (1.9%)
Unknown0 (0.0%)
User Interaction
None40 (76.9%)
Unknown0 (0.0%)
Required12 (23.1%)
Privileges Required
Low15 (28.8%)
High1 (1.9%)
None36 (69.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (52 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
3.8% of CVEs· 98th percentile
Nuclei
3 CVEs
5.8% of CVEs· 96th percentile
ExploitDB
2 CVEs
3.8% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gitea Limited.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gitea Limited — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gitea Limited's Products

View all 5 CNAs →

Top CWEs