Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18995 | Gogs XSS allowed by stored call in PDF renderer |
Github GHSA |
GHSA-xh32-cx6c-cp4v | Gogs XSS allowed by stored call in PDF renderer |
Wed, 30 Jul 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 24 Jun 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Jun 2025 04:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gogs is an open source self-hosted Git service. In application version 0.14.0+dev and prior, there is a stored cross-site scripting (XSS) vulnerability present in Gogs, which allows client-side Javascript code execution. The vulnerability is caused by the usage of a vulnerable and outdated component: pdfjs-1.4.20 under public/plugins/. This issue has been fixed for gogs.io/gogs in version 0.13.3. | |
| Title | Gogs stored XSS in PDF renderer | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-07-30T17:45:57.812Z
Reserved: 2025-05-14T10:32:43.530Z
Link: CVE-2025-47943
Updated: 2025-06-24T21:48:42.035Z
Status : Deferred
Published: 2025-06-24T04:15:46.743
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-47943
No data.
OpenCVE Enrichment
Updated: 2025-07-06T22:16:32Z
EUVD
Github GHSA