Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Maluff

#19106of 56,326
15Total CVSS
Vulnerabilities · 2
High
2
PT-2026-63292
7.5
2026-07-21
Gitea · Gitea · CVE-2026-58417
**Name of the Vulnerable Software and Affected Versions** Gitea (affected versions not specified) **Description** The REST API exposes organization membership of public members within a private organization. An unauthorized user can determine if a specific user is a member of a private organization by sending a GET request to the endpoint "/orgs/{org}/public members/{username}". This information is otherwise hidden from the web application and the user's profile page. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-55593
7.5
2026-07-03
Gitea · Gitea · CVE-2026-25712
**Name of the Vulnerable Software and Affected Versions** Gitea versions prior to 1.25.5 **Description** Insufficient visibility checks exist within organization permission APIs, which may affect hidden members and private organizations. **Recommendations** Update to version 1.25.5 or later.