VYPR
Medium severity6.1NVD Advisory· Published Jan 28, 2020· Updated Jun 17, 2026

CVE-2019-15586

CVE-2019-15586

Description

A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

Affected products

4
  • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*+ 1 more
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:community:*:*:*range: >=12.1.0,<12.1.10
    • cpe:2.3:a:gitlab:gitlab:*:*:*:*:enterprise:*:*:*range: >=12.1.0,<12.1.10
  • Range: <12.1.10
  • GitLab Inc./CE/EEcpe-rescue
    Range: before 12.1.10

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.