Gogs Vulnerabilities Lead to XSS and Token Leakage Risks
Article Content
Browse articles
Gogs, an open source self-hosted Git service, has two critical vulnerabilities prior to version 0.14.2. CVE-2026-26276 allows attackers to execute a DOM-Based XSS via malicious HTML/JavaScript in Milestone names, while CVE-2026-26196 exposes sensitive tokens in URLs, risking data leakage through logs and referrers. Both issues have been patched in version 0.14.2.
Ask AI about this cluster
Answers cite the sources they use
Updated 212d ago How this analysis works
Timeline
2026-03-05
CVE-2026-26196 published
2026-03-05
CVE-2026-26276 published
Recent
Patch released for both vulnerabilities
More articles in this cluster (4)
Following this threat?
Track Gogs and CVE-2026-26194 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates Three WordPress plugins have been reported with vulnerabilities: the GiveWP plugin (version 4.16.9) has a Cross Site Scripting (XSS) vulnerability, while both the Siteskite (version 2.1.8) and Cartflows (version 3.2.0) plugins have Remote Code Execution (RCE) vulnerabilities. The XSS vulnerability allows attackers to…