CVE-2024-6886: Gitea

Critical severity, CVSS 10.0. EPSS: 33% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Gitea Gitea Open Source Git Server allows Stored XSS.This issue affects Gitea Open Source Git Server: 1.22.0.

Affected products

  • Gitea Gitea: version 1.22.0 only
  • Gitea Gitea Open Source Git Server: version 1.22.0 only

Published 2024-08-06. Last modified 2026-06-17.