Forgejo

Forgejo

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.16%
  • Veröffentlicht 13.09.2026 03:55:04
  • Zuletzt bearbeitet 22.09.2026 20:00:03

Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does not verify that the HTTP Signature on an incoming Acti...

  • EPSS 0.15%
  • Veröffentlicht 11.09.2026 02:23:27
  • Zuletzt bearbeitet 22.09.2026 20:00:03

Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.

  • EPSS 0.5%
  • Veröffentlicht 10.09.2026 20:42:18
  • Zuletzt bearbeitet 22.09.2026 20:00:03

Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.

Exploit
  • EPSS 0.21%
  • Veröffentlicht 30.08.2026 17:45:08
  • Zuletzt bearbeitet 31.08.2026 20:56:08

A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migrations/allowlist/is_migrate_allowed.go of the component Repository Migration Handler. Performing a manipulation results in server...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 02.07.2026 19:44:07
  • Zuletzt bearbeitet 06.07.2026 19:01:14

Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arbitrary JavaScript in other users' browsers by setting a full name containing an HTML payload and triggering an Actions run. W...

  • EPSS 0.47%
  • Veröffentlicht 16.03.2026 00:00:00
  • Zuletzt bearbeitet 27.04.2026 19:18:46

In Forgejo through 13.0.3, the attachment component allows a denial of service by uploading a multi-gigabyte file attachment (e.g., to be associated with an issue or a release).

  • EPSS 0.48%
  • Veröffentlicht 25.12.2025 23:57:30
  • Zuletzt bearbeitet 15.04.2026 00:35:42

Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and late...

  • EPSS 0.87%
  • Veröffentlicht 03.12.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:34:03

In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform ...

  • EPSS 0.61%
  • Veröffentlicht 03.12.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:34:03

Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.

  • EPSS 0.81%
  • Veröffentlicht 03.12.2023 19:15:08
  • Zuletzt bearbeitet 21.11.2024 08:34:03

Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.