Vulnerabilities
CVE-2026-29084 - Gokapi: CSRF in Login Endpoint
CVE ID : CVE-2026-29084 Published : March 6, 2026, 5:16 a.m. | 35 minutes ago Description : Gokapi is a self-hosted file sharing server with automatic expiration and encryption support. Prior to version 2.2.3, the login flow accepts credential-bearing requests without CSRF protection mechanisms tied to the browser session context. The handler parses form values directly and creates a session on successful credential validation. This issue has been patched in version 2.2.3. Severity: 4.6 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...