forgejo
DevTools & CIoss-project
Top products
Latest CVEs
The 8 most recently published vulnerabilities affecting forgejo.
- CVE-2026-90679Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrity but does not allow account takeover or content modification. It does n...4.3
- CVE-2026-89151Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature.3.5
- CVE-2026-89094Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .forgejo/template is mishandled.9.9
- CVE-2026-59102Forgejo < 15.0.3 - Stored XSS via Actions Run Full Name Rendering5.4
- CVE-2025-68937Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositor...9.0
- CVE-2023-49947Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.7.5
- CVE-2023-49948Forgejo before 1.20.5-1 allows remote attackers to test for the existence of private user accounts by appending .rss (or another extension) to a URL.5.3
- CVE-2023-49946In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, re...9.1