Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3c22-5j5m-4jq7 | Gokapi has Stored XSS in SVG Hotlinks |
Mon, 09 Mar 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:forceu:gokapi:*:*:*:*:*:*:*:* |
Fri, 06 Mar 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 06 Mar 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Forceu
Forceu gokapi |
|
| Vendors & Products |
Forceu
Forceu gokapi |
Fri, 06 Mar 2026 05:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads SVG and creates a hotlink for it, they can achieve stored XSS. This issue has been patched in version 2.2.3. | |
| Title | Gokapi: Stored XSS in SVG Hotlinks | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-03-06T16:06:43.449Z
Reserved: 2026-03-02T21:43:19.927Z
Link: CVE-2026-28683
Updated: 2026-03-06T15:58:14.419Z
Status : Analyzed
Published: 2026-03-06T05:16:38.443
Modified: 2026-03-09T18:52:48.920
Link: CVE-2026-28683
No data.
OpenCVE Enrichment
Updated: 2026-04-16T11:45:26Z
Github GHSA