CVE-2025-68946 – Gitea JavaScript URL Scheme XSS Vulnerability
CVE ID : CVE-2025-68946
Published : Dec. 26, 2025, 5:16 a.m. | 1 hour, 6 minutes ago
Description : In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS.
Severity: 5.4 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more…