CVE
CVE-2014-8682
7.5
CVSS
Description
Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go.
Attack Vector
-
Privileges Req.
-
User Interaction
-
Updated Sep 22, 2026View on NVD →
This CVE is in S4E's catalog, but no public scanner is mapped to it yet.
Monitor this CVE on your assets
S4E maps published CVEs to scanners and forecasts the next disclosure window for your stack.
Create a free account →