{"id":"CVE-2022-1464","aliases":["GHSA-ff28-f46g-r9g8","GO-2022-0597"],"url":"https://o3.security/vulnerability/CVE-2022-1464","summary":"Stored xss bug  in gogs/gogs","details":"Stored xss bug in GitHub repository gogs/gogs prior to 0.12.7. As the repo is public , any user can view the report and when open the attachment then xss is executed. This bug allow executed any javascript code in victim account .","published":"2022-05-05T13:45:12Z","modified":"2026-08-12T03:51:45.401854360Z","cvss":{"score":7.3,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"Go","name":"gogs.io/gogs","fixedVersion":"0.12.7"}],"fix":{"url":"https://github.com/gogs/gogs/commit/bc77440b301ac8780698be91dff1ac33b7cee850","label":"gogs/gogs@bc77440"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/34a12146-3a5d-4efc-a0f8-7a3ae04b198d"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/1xxx/CVE-2022-1464.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-1464"},{"type":"FIX","url":"https://github.com/gogs/gogs/commit/bc77440b301ac8780698be91dff1ac33b7cee850"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:45.401854360Z"}}