Vulnerabilities in Gitea
23 resultsCVE-2026-0798LOWGitea Release Email Notifications Leak Private Repository Release Details After Access RevocationEPSS 0.2%CVE-2025-68942MEDIUMGitea before 1.22.2 allows XSS because the search input box (for creating tags and branches) is v-html instead of v-text.EPSS 0.2%CVE-2025-68946MEDIUMIn Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.EPSS 0.2%