<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Forgejo (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/forgejo.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/forgejo-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Forgejo (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:26:58 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2025-68937 – Forgejo before 13.0.2 allows attackers to write to unintended files, and possibl...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2025-68937</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2025-68937</guid>
    <pubDate>Fri, 26 Dec 2025 00:16:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2025-68937</strong></p>
  <p>Forgejo before 13.0.2 allows attackers to write to unintended files, and possibly obtain server shell access, because of mishandling of out-of-repository symlink destinations for template repositories. This is also fixed for 11 LTS in 11.0.7 and later.</p>
  <p><strong>CVSS:</strong> 9.5 · <strong>CWE:</strong> CWE-61</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-68937">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2023-49947 – Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentic...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49947</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49947</guid>
    <pubDate>Sun, 03 Dec 2023 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2023-49947</strong></p>
  <p>Forgejo before 1.20.5-1 allows 2FA bypass when docker login uses Basic Authentication.</p>
  <p><strong>CVSS:</strong> 7.5 · <strong>CWE:</strong> CWE-863</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49947">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2023-49946 – In Forgejo before 1.20.5-1, certain endpoints do not check whether an object bel...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2023-49946</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2023-49946</guid>
    <pubDate>Sun, 03 Dec 2023 19:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2023-49946</strong></p>
  <p>In Forgejo before 1.20.5-1, certain endpoints do not check whether an object belongs to a repository for which permissions are being checked. This allows remote attackers to read private issues, read private pull requests, delete issues, and perform other unauthorized actions.</p>
  <p><strong>CVSS:</strong> 9.1 · <strong>CWE:</strong> CWE-732</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2023-49946">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
