CVE-2014-8681: Gogits Gogs
High severity, CVSS 7.5. EPSS: 4.4% chance of exploitation in the next 30 days.
SQL injection vulnerability in the GetIssues function in models/issue.go in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.6.x before 0.5.6.1025 Beta allows remote attackers to execute arbitrary SQL commands via the label parameter to user/repos/issues.
Affected products
- Gogits Gogs: up to and including 0.5.5; version 0.3.1-9 only; version 0.4.1 only; version 0.4.2 only; version 0.5.0 only; version 0.5.2 only
Published 2014-11-21. Last modified 2026-06-17.