Broken Authentication
Gitea
An archive of identified vulnerabilities and security research. Documenting structural flaws in high-value systems to advance defensive strategies.
64
Total CVEs
15
Critical Findings
7
Years Active
| ID | Type | Product | Severity | Link |
|---|---|---|---|---|
| CVE-2026-20896 | Broken Authentication | Gitea | Critical | View |
| CVE-2026-25119 | Broken Authentication | Gogs | Medium | View |
| CVE-2026-9065 | SQL Injection | Surecart | Medium | View |
| CVE-2026-9059 | SQL Injection | NextGEN Gallery | Medium | View |
| CVE-2026-44706 | SQL Injection | Chatwoot | High | View |
| TRA-2026-32 | Path Traversal | Flowise | Medium | View |
| CVE-2026-41274 | SQL Injection | Flowise | High | View |
| CVE-2026-30824 | Broken Authentication | Flowise | High | View |
| TRA-2026-34 | Sensitive Information Disclosure | Flowise | Medium | View |
| CVE-2026-5027 | Path Traversal | Langflow | High | View |
| CVE-2026-5026 | Stored XSS | Langflow | High | View |
| CVE-2026-5025 | Broken Authentication | Langflow | Medium | View |
| CVE-2026-5022 | Broken Authentication | Langflow | Low | View |
| CVE-2026-4984 | SSRF | Botpress | High | View |
| TRA-2026-21 | Authorization Bypass | Midday | Medium | View |
| CVE-2026-27944 | Sensitive Information Disclosure | Nginx UI | Critical | View |
| CVE-2026-3432 | Sensitive Information Disclosure | SimStudio | Critical | View |
| CVE-2026-3431 | SSRF | SimStudio | Critical | View |
| CVE-2026-27167 | Sensitive Information Disclosure | Gradio | High | View |
| CVE-2026-2577 | Broken Authentication | Nanobot | Critical | View |
| CVE-2026-25120 | Broken Authentication | Gogs | Medium | View |
| TRA-2025-50 | Exposed API Key | WordPress Plugin | Medium | View |
| TRA-2025-34 | SSRF Bypass | BentoML | High | View |
| TRA-2025-33 | Exposed API Key | WordPress Plugin | Medium | View |
| TRA-2025-32 | Exposed API Key | WordPress Plugin | Medium | View |
| CVE-2025-2304 | Privilege Escalation | Camaleon CMS | High | View |
| CVE-2024-12015 | SQL Injection | WordPress Plugin | High | View |
| CVE-2024-10859 | SQL Injection | WordPress Plugin | Critical | View |
| CVE-2024-9148 | Stored XSS | FlowiseAI | Medium | View |
| CVE-2024-8182 | Denial of Service | FlowiseAI | High | View |
| CVE-2024-7790 | Stored XSS | Stition AI | Medium | View |
| CVE-2024-7297 | Privilege Escalation | Langflow AI | High | View |
| CVE-2024-4960 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2024-4959 | Stored XSS | Solidus | Medium | View |
| CVE-2024-1063 | Blind SSRF | AppWrite | Medium | View |
| CVE-2024-1061 | SQL Injection | WordPress Plugin | Critical | View |
| CVE-2023-6360 | SQL Injection | WordPress Plugin | Critical | View |
| CVE-2023-4137 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2023-28667 | Insecure Deserialization | WordPress Plugin | Critical | View |
| CVE-2023-28666 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2023-28665 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2023-28664 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2023-28663 | SQL Injection | WordPress Plugin | High | View |
| CVE-2023-28662 | SQL Injection | WordPress Plugin | Critical | View |
| CVE-2023-28661 | SQL Injection | WordPress Plugin | High | View |
| CVE-2023-28660 | SQL Injection | WordPress Plugin | High | View |
| CVE-2023-28659 | SQL Injection | WordPress Plugin | High | View |
| CVE-2023-28017 | Stored XSS | CraftCMS | Medium | View |
| CVE-2023-26326 | Insecure Deserialization | WordPress Plugin | Critical | View |
| CVE-2023-26325 | SQL Injection | WordPress Plugin | High | View |
| CVE-2023-23492 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2023-23491 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2023-23490 | SQL Injection | WordPress Plugin | High | View |
| CVE-2023-23489 | SQL Injection | WordPress Plugin | Critical | View |
| CVE-2023-23488 | SQL Injection | WordPress Plugin | Critical | View |
| CVE-2023-0448 | Reflected XSS | WordPress Plugin | Medium | View |
| CVE-2022-1731 | SQL Injection | Metasonic | Critical | View |
| CVE-2022-38131 | Open Redirect | RStudio | Medium | View |
| CVE-2021-41262 | SQL Injection | Galette | High | View |
| CVE-2021-41261 | Stored XSS | Galette | Medium | View |
| CVE-2021-41260 | CSRF | Galette | Medium | View |
| CVE-2020-25070 | CSRF | USVN | Medium | View |
| CVE-2020-25069 | RCE | USVN | Critical | View |
| CVE-2020-15081 | Information Disclosure | PrestaShop | Medium | View |
Gitea
Gogs
Surecart
NextGEN Gallery
Chatwoot
Flowise
Flowise
Flowise
Flowise
Langflow
Langflow
Langflow
Langflow
Botpress
Midday
Nginx UI
SimStudio
SimStudio
Gradio
Nanobot
Gogs
WordPress Plugin
BentoML
WordPress Plugin
WordPress Plugin
Camaleon CMS
WordPress Plugin
WordPress Plugin
FlowiseAI
FlowiseAI
Stition AI
Langflow AI
WordPress Plugin
Solidus
AppWrite
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
CraftCMS
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
WordPress Plugin
Metasonic
RStudio
Galette
Galette
Galette
USVN
USVN
PrestaShop
Showing 64 of 64 results