{"id":"CVE-2021-28378","details":"Gitea 1.12.x and 1.13.x before 1.13.4 allows XSS via certain issue data in some situations.","aliases":["BIT-gitea-2021-28378","GHSA-g95p-88p4-76cm","GO-2022-0832"],"modified":"2026-08-07T15:15:35.167196Z","published":"2021-03-15T06:15:12.423Z","references":[{"type":"ADVISORY","url":"https://blog.gitea.io/2021/03/gitea-1.13.4-is-released/"},{"type":"FIX","url":"https://github.com/go-gitea/gitea/pull/14898"},{"type":"EVIDENCE","url":"https://github.com/PandatiX/CVE-2021-28378"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/go-gitea/gitea","events":[{"introduced":"d6657644a96417d2e771a2891a54e99e686be0a3"},{"last_affected":"53b89c34742855e0c5a7f989d6506f02791678af"},{"introduced":"03b7e11bd6125d4128cf99bc408723d1548f0613"},{"fixed":"75496b9ff507ca5e9b7665f888f1156485e6532d"}],"database_specific":{"cpe":"cpe:2.3:a:gitea:gitea:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.12.0"},{"last_affected":"1.12.6"},{"introduced":"1.13.0"},{"fixed":"1.13.4"}],"source":"CPE_RANGE"}}],"versions":["v1.13.3","v1.13.2","v1.13.1","v1.13.0","v1.12.6","v1.13.0-rc2","v1.13.0-rc1","v1.12.5","v1.12.4","v1.12.3","v1.12.2","v1.12.1","v1.12.0","v1.12.0-rc2","v1.12.0-rc1","v1.13.0-dev","v1.12.0-dev"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-28378.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}