Pagure
Vendor:
First CVE: Oct 7, 2016 · Active for 9 years
7
Total CVEs
More Total CVEs than 85% of tracked products
1.4
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 33% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pagure over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 7, 2016
9 years ago
Most Recent CVE
May 12, 2025
441 days ago
CVE Severity & Scoring
Pagure7 CVEs
71%
29%
All CVEs352,785 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network7 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low6 (85.7%)
High1 (14.3%)
Unknown0 (0.0%)
User Interaction
None4 (57.1%)
Unknown0 (0.0%)
Required3 (42.9%)
Privileges Required
Low2 (28.6%)
High0 (0.0%)
None5 (71.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-1002151HIGH Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization | Sep 14, 2017 | 7.5 | 24 | NO | NO |
CVE-2019-11556MEDIUM Pagure before 5.6 allows XSS via the templates/blame.html blame view. | Sep 25, 2020 | 6.1 | 22 | NO | NO |
CVE-2016-1000007MEDIUM Pagure 2.2.1 XSS in raw file endpoint | Oct 7, 2016 | 6.1 | 21 | NO | NO |
CVE-2019-7628MEDIUM Pagure 5.2 leaks API keys by e-mailing them to users. Few e-mail servers validate TLS certificates, so it is easy for man-in-the-middle attackers to read these e-mails and gain acc | Feb 8, 2019 | 5.9 | 20 | NO | NO |
CVE-2024-4982MEDIUM A directory traversal vulnerability was discovered in Pagure server. If a malicious user submits a specially cratfted git repository they could discover secrets on the server. | May 12, 2025 | 6.5 | 19 | NO | NO |
CVE-2024-4981HIGH A vulnerability was discovered in Pagure server. If a malicious user were to submit a git repository with symbolic links, the server could unintentionally show incorporate and make | May 12, 2025 | 7.1 | 19 | NO | NO |
CVE-2016-1000037MEDIUM Pagure: XSS possible in file attachment endpoint | Nov 6, 2019 | 6.1 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (7 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (7 CVEs).
Media Mentions
Signals from CVEs in this product scope (7 CVEs).
Top CNAs Publishing CVEs For Pagure
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 5.2 | 1 | 5.9 | 0.9% | 0 | 0 |
| 2.2.1 | 1 | 6.1 | 0.7% | 0 | 0 |