VYPR

gitlab-org/gitlab-ee

by GitLab Inc.

Source repositories

CVEs (297)

  • CVE-2021-39885HigOct 4, 2021
    risk 0.57cvss 8.7epss 0.01

    A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's…

  • CVE-2018-19359HigApr 25, 2019
    risk 0.57cvss 8.8epss 0.02

    GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

  • CVE-2026-79708HigSep 16, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.0 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions could have allowed an authenticated user with developer permissions to execute a policy test pipeline on projects…

  • CVE-2026-88765HigSep 15, 2026
    risk 0.55cvss 8.5epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 12.3 to 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 under certain conditions could allow an authenticated user to achieve remote code execution by importing a specially crafted Git project export to…

  • CVE-2026-19228HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.4 and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user to cause AI usage to be attributed to another namespace, due to improper authorization of…

  • CVE-2025-11702HigOct 29, 2025
    risk 0.55cvss 8.5epss 0.01

    GitLab has remediated an issue in EE affecting all versions from 17.1 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker with specific permissions to hijack project runners from other projects.

  • CVE-2023-3399HigNov 6, 2023
    risk 0.55cvss 8.5epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 11.6 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 before 16.5.1. It was possible for an unauthorised project or group member to read the CI/CD…

  • CVE-2023-5009HigSep 19, 2023
    risk 0.54cvss 8.2epss 0.10

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.2.7, all versions starting from 16.3 before 16.3.4. It was possible for an attacker to run pipeline jobs as an arbitrary user via scheduled security scan policies. This was a bypass of…

  • CVE-2026-4868HigMay 27, 2026
    risk 0.53cvss 8.2epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authenticated user to cause specific Duo AI workflows to run under another user's…

  • CVE-2024-8114HigNov 26, 2024
    risk 0.53cvss 8.2epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 8.12 before 17.4.5, 17.5 before 17.5.3, and 17.6 before 17.6.1. This issue allows an attacker with access to a victim's Personal Access Token (PAT) to escalate privileges.

  • CVE-2024-8977HigOct 10, 2024
    risk 0.53cvss 8.2epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 15.10 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. Instances with Product Analytics Dashboard configured and enabled could be vulnerable to SSRF attacks.

  • CVE-2023-3932HigAug 3, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 13.12 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. It was possible for an attacker to run pipeline jobs as an arbitrary user via…

  • CVE-2023-3484HigJul 21, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 12.8 before 15.11.11, all versions starting from 16.0 before 16.0.7, all versions starting from 16.1 before 16.1.2. An attacker could change the name or path of a public top-level group in certain…

  • CVE-2020-13275HigJun 19, 2020
    risk 0.52cvss 8.0epss 0.01

    A user with an unverified email address could request an access to domain restricted groups in GitLab EE 12.2 and later through 13.0.1

  • CVE-2022-1940HigJun 6, 2022
    risk 0.51cvss 7.7epss 0.06

    A Stored Cross-Site Scripting vulnerability in Jira integration in GitLab EE affecting all versions from 13.11 prior to 14.9.5, 14.10 prior to 14.10.4, and 15.0 prior to 15.0.1 allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf via specially…

  • CVE-2026-92470HigSep 24, 2026
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to access sensitive CI/CD variable values from debug-mode job traces…

  • CVE-2026-2995HigMar 25, 2026
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 15.4 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an authenticated user to add email addresses to targeted user accounts due to improper sanitization of HTML content.

  • CVE-2025-11340HigOct 9, 2025
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting…

  • CVE-2025-1908HigApr 24, 2025
    risk 0.50cvss 7.7epss 0.00

    An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

  • CVE-2025-0555HigMar 3, 2025
    risk 0.50cvss 7.7epss 0.00

    A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

Page 2 of 15