CVE-2020-14958: Gogs
Medium severity, CVSS 6.5. EPSS: 0.9% chance of exploitation in the next 30 days.
In Gogs 0.11.91, MakeEmailPrimary in models/user_mail.go lacks a "not the owner of the email" check.
Affected products
- Gogs Gogs: version 0.11.91 only
Published 2020-06-21. Last modified 2026-06-17.