CVE-2025-68946 - Gitea JavaScript URL Scheme XSS Vulnerability

CVE-2025-68946 - Gitea JavaScript URL Scheme XSS Vulnerability

CVE ID : CVE-2025-68946 Published : Dec. 26, 2025, 5:16 a.m. | 1 hour, 10 minutes ago Description : In Gitea before 1.20.1, a forbidden URL scheme such as javascript: can be used for a link, aka XSS. Severity: 5.4 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
MEDIUM
Published
Dec. 26, 2025
Impact: XSS

Source: Telegram CVE Monitor