Known Vulnerabilities for Forgejo by Na
Listed below are 6 of the newest known vulnerabilities associated with "Forgejo" by "Na".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-90679 json | Forgejo 13.0.0 through 16.0.4, when "[federation] ENABLED = true" is set, has a spoofing issue that affects identity integrit... | Not Provided | 2026-09-13 | 2026-09-15 |
| CVE-2026-89151 json | Forgejo before 16.0.4 allows use of restricted API tokens for unintended access to the "allow maintainer edit" feature. | Not Provided | 2026-09-11 | 2026-09-11 |
| CVE-2026-89094 json | Forgejo before 16.0.4 allows remote code execution via a crafted template repository because template expansion on files in .... | Not Provided | 2026-09-10 | 2026-09-14 |
| CVE-2026-82556 json | A vulnerability was found in Forgejo up to 15.0.4. This issue affects the function net.LookupIP of the file services/migratio... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-59102 json | Forgejo before 15.0.3 contains a stored cross-site scripting vulnerability that allows authenticated attackers to execute arb... | Not Provided | 2026-07-02 | 2026-07-06 |
| CVE-2026-58370 json | Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, p... | Not Provided | 2026-06-30 | 2026-07-14 |