CVE-2020-14958: Gogs

Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.

In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.

Affected products

  • Gogs Gogs: version 0.11.91 only

Published 2020-06-21. Last modified 2026-06-17.