Reflected Cross Site Scripting and Header Injection in Mimetype Query String in cgit before 0.12 (CVE-2016-1899).
Stored Cross Site Scripting and Header Injection in Filename Parameter in cgit before 0.12 (CVE-2016-1900).
Integer Overflow resulting in Buffer Overflow in cgit before 0.12 (CVE-2016-1901).