Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Gogs

First CVE: Aug 8, 2018Active for: 8 yearsTotal CVEs: 49
83.1
VTI Score
TOP TARGET

Gogs is a self-hosted Git service designed for smaller teams and organizations, presenting a narrowly scoped but strategically important attack surface as it often runs in trusted internal environments and manages source-code access. Vulnerabilities affecting the product skew strongly toward critical severity and frequently acquire public exploit code, reflecting the authentication, input handling, and system integration demands of a code-repository application. The exposure recurs persistently through path-traversal, cross-site scripting, missing authorization, OS command injection, and server-side request forgery weaknesses—a pattern characteristic of user-facing web services that interact with underlying version-control operations and file systems. Because Gogs deployments often control access to sensitive codebases and CI/CD systems, these vulnerability classes carry outsized impact relative to the product's narrow user base. Live exploitation activity and severity counts are shown alongside this summary.

FAUCET AI Generated
49
Total CVEs
More Total CVEs than 98% of tracked vendors
6.1
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.9
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
2.0%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Gogs over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 8, 2018
7 years ago
Most Recent CVE
Mar 5, 2026
142 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-8110HIGH
Improper Symbolic link handling in the PutContents API in Gogs allows Local Execution of Code.
Dec 10, 20258.897YESYES
CVE-2022-2024CRITICAL
OS Command Injection in GitHub repository gogs/gogs prior to 0.12.11.
Feb 25, 20239.883NONO
CVE-2020-15867HIGH
The git hook feature in Gogs 0.5.5 through 0.12.2 allows for authenticated remote code execution. There can be a privilege escalation if access to this hook feature is granted to a
Oct 16, 20207.281NOYES
CVE-2022-0415HIGH
Remote Command Execution in uploading repository file in GitHub repository gogs/gogs prior to 0.12.6.
Mar 21, 20228.875NOYES
CVE-2024-55947HIGH
Gogs is an open source self-hosted Git service. A malicious user is able to write a file to an arbitrary path on the server to gain SSH access to the server. The vulnerability is f
Dec 23, 20248.868NONO
CVE-2022-32174CRITICAL
In Gogs, versions v0.6.5 through v0.12.10 are vulnerable to Stored Cross-Site Scripting (XSS) that leads to an account takeover.
Oct 11, 20229.060NONO
CVE-2018-18925CRITICAL
Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go.
Nov 4, 20189.860NOYES
CVE-2024-39931CRITICAL
Gogs through 0.13.0 allows deletion of internal files.
Jul 4, 20249.959NONO
CVE-2024-39930CRITICAL
The built-in SSH server of Gogs through 0.13.0 allows argument injection in internal/ssh/ssh.go, leading to remote code execution. Authenticated attackers can exploit this by openi
Jul 4, 20249.947NOYES
CVE-2022-1993HIGH
Path Traversal in GitHub repository gogs/gogs prior to 0.12.9.
Jun 9, 20228.146NONO
View all 49 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products49 CVEs
33%
33%
33%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local0 (0.0%)
Network49 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low48 (98.0%)
High1 (2.0%)
Unknown0 (0.0%)
User Interaction
None38 (77.6%)
Unknown0 (0.0%)
Required11 (22.4%)
Privileges Required
Low23 (46.9%)
High3 (6.1%)
None23 (46.9%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (49 CVEs).

CISA KEV
1 CVE
2.0% of CVEs· 99th percentile
Metasploit
1 CVE
2.0% of CVEs· 97th percentile
Nuclei
5 CVEs
10.2% of CVEs· 96th percentile
ExploitDB
1 CVE
2.0% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Gogs.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Gogs — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Gogs's Products

View all 5 CNAs →

Top CWEs