References https://nvd.nist.gov/vuln/detail/CVE-2022-2024 https://github.com/advisories/GHSA-pfvh-p8qp-9ww9 https://www.miggo.io/vulnerability-database/cve/CVE-2022-2024 https://vulners.com/osv/OSV:GHSA-PFVH-P8QP-9WW9 https://github.com/gogs/gogs/security/advisories/GHSA-pfvh-p8qp-9ww9 https://vulmon.com/searchpage?q=gogs https://feedly.com/cve/vendors/gogs https://vuldb.com/vuln/221789 https://socradar.io/free-tools/cve-radar/CVE-2022-2024 https://advisories.checkpoint.com/defense/advisories/public/2023/cpai-2022-1493.html/ https://www.juniper.net/us/en/threatlabs/ips-signatures/detail.HTTP:CTS:GOGS-CMD-INJ.html https://docs.devguard.org/vulnerability-database/GHSA-pfvh-p8qp-9ww9/ https://techjacksolutions.com/scc-intel/unpatched-gogs-rce-authenticated-users-can-compromise-any-instance-via-git-rebase-injection/ https://docs.sophos.com/releasenotes/output/en-us/nsg/IPSReleaseNotes/7.20.29_s.pdf https://update.nsfocusglobal.com/update/listNewipsDetail/v/rule5.6.11_v2 https://autoupdate.ngfw.forcepoint.com/download/dynup/1570-5242-RLNT.html https://autoupdate.ngfw.forcepoint.com/download/dynup/sgpkg-1983-SUMMARY.html https://update.nsfocusglobal.com/update/listNewipsDetail/v/rule5.6.10
Related VulnerabilitiesPoCCVE-2026-5524: Divi Form Builder <=5.1.8 - Unauthenticated Arbitrary File Upload RCEPoCCVE-2026-32475: Elementor Pro <=4.2.1 - Unauthenticated Arbitrary File Upload via Form HandlerFileRise /uploads 文件读取漏洞(CVE-2026-25231)鎧應科技|CMS-WS/CMS-SE/SMP - Arbitrary File Upload網韻資訊|NewSiteServer (NSS)新式校園網站系統 - Arbitrary File UploadPoCCVE-2026-0558: LolLMS <= 2.2.0 - Unauthenticated File UploadPoCCVE-2026-13001: Podlove Podcast Publisher <= 4.5.1 - Arbitrary File UploadPoCCVE-2026-52806: Gogs <= 0.14.2 - Authenticated RCE via git rebase Argument InjectionPoCCVE-2026-57827: RSFiles! for Joomla - Arbitrary File UploadPoCmonitorr-file-upload: Monitorr Services Configuration - Arbitrary File Upload二一零零科技|公文管理系統 - Arbitrary File UploadPoCCVE-2024-56064: WP SuperBackup <= 2.3.3 - Unauthenticated Arbitrary File Upload to RCEPoCCVE-2026-14483: Realtyna Organic IDX/WPL <= 5.2.0 - Unauthenticated Arbitrary File Upload