Exposição de Gitea

Development
25
score de exposição
50
sites usam
1
em exploração
1
críticos
Análise Vexday

Com 12 CVEs catalogadas e nenhuma em exploração ativa confirmada pelo CISA KEV, o Gitea apresenta taxa de exploração abaixo da média geral do catálogo, o que indica perfil de risco moderado no contexto atual. Não há vulnerabilidades críticas registradas nem entradas novas nos últimos 90 dias, sugerindo estabilidade recente no volume de descobertas. O tipo de falha mais recorrente é CWE-863 (autorização incorreta), o que aponta para atenção necessária em controles de acesso e verificação de permissões na plataforma. A CVE mais relevante no momento, CVE-2019-1010261, exibe EPSS de 0,0084, valor baixo que reflete probabilidade reduzida de exploração iminente, mas ainda merece acompanhamento em ambientes que não aplicaram as correções disponíveis.

CVEs

14 resultados
CVE-2026-60004CRITICALGitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.EPSS 86.8%KEVCVE-2019-1010314Gitea 1.7.2, 1.7.3 is affected by: Cross Site Scripting (XSS). The impact is: execute JavaScript in victim's browser, when the vulnerable reEPSS 0.8%CVE-2019-1010261Gitea 1.7.0 and earlier is affected by: Cross Site Scripting (XSS). The impact is: Attacker is able to have victim execute arbitrary JS in bEPSS 0.8%CVE-2025-69413MEDIUMIn Gitea before 1.25.2, /api/v1/user has different responses for failed authentication depending on whether a username exists.EPSS 0.4%CVE-2025-68938MEDIUMGitea before 1.25.2 mishandles authorization for deletion of releases.EPSS 0.4%CVE-2025-68945MEDIUMIn Gitea before 1.21.2, an anonymous user can visit a private user's project.EPSS 0.4%CVE-2025-68943MEDIUMGitea before 1.21.8 inadvertently discloses users' login times by allowing (for example) the lastlogintime explore/users sort order.EPSS 0.4%CVE-2025-68939HIGHGitea before 1.23.0 allows attackers to add attachments with forbidden file extensions by editing an attachment name via an attachment API.EPSS 0.3%CVE-2026-34966HIGHGitea prior to 1.27.0 SSRF via Migration URI Fetch BypassEPSS 0.3%CVE-2025-68944MEDIUMGitea before 1.22.2 sometimes mishandles the propagation of token scope for access control within one of its own package registries.EPSS 0.3%CVE-2025-68940LOWIn Gitea before 1.22.5, branch deletion permissions are not adequately enforced after merging a pull request.EPSS 0.3%CVE-2025-68941MEDIUMGitea before 1.22.3 mishandles access to a private resource upon receiving an API token with scope limited to public resources.EPSS 0.3%CVE-2025-68942MEDIUMGitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.EPSS 0.3%CVE-2025-68946MEDIUMIn Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.EPSS 0.3%