« Back to list

Forceu

Forceu Gokapi: vulnerabilities and CVEs

Forceu Gokapi has 10 published vulnerabilities, 8 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs10
Last 12 months8
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-30961Medium (4.3)0.28%—Mar 13, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate the total file size against the…
CVE-2026-30955Medium (6.5)0.29%—Mar 13, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an…
CVE-2026-30943Medium (4.1)0.20%—Mar 13, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility…
CVE-2026-29084Medium (4.6)0.09%—Mar 6, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the login flow accepts credential-bearing requests without CSRF protection mechanisms tied to the…
CVE-2026-29061Medium (5.4)0.15%—Mar 6, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user rank demotion logic allows a demoted user's existing…
CVE-2026-29060Medium (5)0.17%—Mar 6, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file requests is able to create a…
CVE-2026-28683High (8.7)0.24%—Mar 6, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads SVG and creates a hotlink for it, they can achieve stored…
CVE-2026-28682Medium (6.4)0.16%—Mar 6, 2026
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any…
CVE-2025-48495Medium (4.8)0.13%—Jun 2, 2025
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly name of an API key, an authenticated user could inject JS into the API key overview, which would…
CVE-2025-48494Medium (4.8)0.17%—Jun 2, 2025
Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encryption, a stored cross-site scripting vulnerability can be exploited by uploading a file with…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1059.007 JavaScript1
  2. T1189 Drive-by Compromise1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.