Products: 3
    Vulnerabilities: 22
    Known Exploited: 0
    0
    Critical Level Threats
    8
    High Level Threats
    12
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2019-10016

    GForge Advanced Server 6.4.4 allows XSS via the commonsearch.php words parameter, as demonstrated by a snippet/search/?words= substring.

    Last Modified: Nov 21, 2024
    Published: Mar 25, 2019

    CVE-2009-3304

    GForge 4.5.14, 4.7 rc2, and 4.8.2 allows local users to overwrite arbitrary files via a symlink attack on authorized_keys files in users' home directories, related to deb-specific/ssh_dump_update.pl and cronjobs/cvs-cron/ssh_create.php.

    Last Modified: Apr 23, 2026
    Published: Dec 04, 2009

    CVE-2009-3303

    Cross-site scripting (XSS) vulnerability in www/help/tracker.php in GForge 4.5.14, 4.7 rc2, and 4.8.1 allows remote attackers to inject arbitrary web script or HTML via the helpname parameter.

    Last Modified: Apr 23, 2026
    Published: Nov 24, 2009

    CVE-2009-4069

    Multiple cross-site scripting (XSS) vulnerabilities in GForge 4.5.14, 4.7.3, and possibly other versions allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Last Modified: Apr 23, 2026
    Published: Nov 24, 2009

    CVE-2009-4070

    SQL injection vulnerability in GForge 4.5.14, 4.7.3, and possibly other versions allows remote attackers to execute arbitrary SQL commands via unknown vectors.

    Last Modified: Apr 23, 2026
    Published: Nov 24, 2009
    Items Per Page
    Gforge Vulnerabilities & Security CVEs | CVE-DB