VendorsForceugokapiany version
Vulnerabilities

Forceu Marc Bulling (Forceu) Gokapi any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

10CVEs
CVE-2026-28683
Gokapi: Stored XSS in SVG Hotlinks
Published 2026-03-06 · Analyzed
8.7EPSS 0.002
CVE-2026-30955
Gokapi vulnerable to DoS in E2E Metadata Parser
Published 2026-03-13 · Analyzed
6.5EPSS 0.003
CVE-2026-28682
Gokapi: Data Leak in Upload Status Stream
Published 2026-03-06 · Analyzed
6.4EPSS 0.002
CVE-2025-48494
Gokapi vulnerable to stored XSS via uploading file with malicious file name
Published 2025-06-02 · Analyzed
5.4EPSS 0.002
CVE-2026-29061
Gokapi: Privilege escalation via incomplete API-key permission revocation on user rank demotion
Published 2026-03-06 · Analyzed
5.4EPSS 0.001
CVE-2025-48495
Gokapi has stored XSS vulnerability in friendly name for API keys
Published 2025-06-02 · Analyzed
5.4EPSS 0.001
CVE-2026-29060
Gokapi: Privilege escalation with auth token
Published 2026-03-06 · Analyzed
5.0EPSS 0.002
CVE-2026-29084
Gokapi: CSRF in Login Endpoint
Published 2026-03-06 · Analyzed
4.6EPSS 0.001
CVE-2026-30961
Gokapi's File Request MaxSize Limit Bypassed via Multi-Chunk Upload
Published 2026-03-13 · Analyzed
4.3EPSS 0.003
CVE-2026-30943
Gokapi has Privilege Escalation in File Replace
Published 2026-03-13 · Analyzed
4.1EPSS 0.002