Forceu
Forceu Gokapi: vulnerabilities and CVEs
Forceu Gokapi has 10 published vulnerabilities, 8 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs10
Last 12 months8
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-30961 | Medium (4.3) | 0.28% | — | Mar 13, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, the chunked upload completion path for file requests does not validate the total file size against the… |
| CVE-2026-30955 | Medium (6.5) | 0.29% | — | Mar 13, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An API endpoint accepts unbounded request bodies without any size limit. An authenticated user can cause an… |
| CVE-2026-30943 | Medium (4.1) | 0.20% | — | Mar 13, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to 2.2.4, An insufficient authorization check in the file replace API allows a user with only list visibility… |
| CVE-2026-29084 | Medium (4.6) | 0.09% | — | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the login flow accepts credential-bearing requests without CSRF protection mechanisms tied to the… |
| CVE-2026-29061 | Medium (5.4) | 0.15% | — | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a privilege escalation vulnerability in the user rank demotion logic allows a demoted user's existing… |
| CVE-2026-29060 | Medium (5) | 0.17% | — | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, a registered user without privileges to create or modify file requests is able to create a… |
| CVE-2026-28683 | High (8.7) | 0.24% | — | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, if a malicious authenticated user uploads SVG and creates a hotlink for it, they can achieve stored… |
| CVE-2026-28682 | Medium (6.4) | 0.16% | — | Mar 6, 2026 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the upload status SSE implementation on /uploadStatus publishes global upload state to any… |
| CVE-2025-48495 | Medium (4.8) | 0.13% | — | Jun 2, 2025 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. By renaming the friendly name of an API key, an authenticated user could inject JS into the API key overview, which would… |
| CVE-2025-48494 | Medium (4.8) | 0.17% | — | Jun 2, 2025 | Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. When using end-to-end encryption, a stored cross-site scripting vulnerability can be exploited by uploading a file with… |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.