VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (607)

  • CVE-2021-22205CriKEVApr 23, 2021
    risk 0.87cvss 10.0epss 1.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.

  • CVE-2026-85706CriKEVSep 12, 2026
    risk 0.81cvss 10.0epss 0.91

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 18.11.12, 19.0 before 19.0.9, 19.1 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the…

  • CVE-2023-2825CriMay 26, 2023
    risk 0.74cvss 10.0epss 0.72

    An issue has been discovered in GitLab CE/EE affecting only version 16.0.0. An unauthenticated malicious user can use a path traversal vulnerability to read arbitrary files on the server when an attachment exists in a public project nested within at least five groups.

  • CVE-2022-2992CriOct 17, 2022
    risk 0.74cvss 9.9epss 0.86

    A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated user to achieve remote code execution via the Import from GitHub API endpoint.

  • CVE-2022-2884CriOct 17, 2022
    risk 0.73cvss 9.9epss 0.76

    A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authenticated user to achieve remote code execution via the Import from GitHub API endpoint

  • CVE-2022-0735CriMar 28, 2022
    risk 0.66cvss 10.0epss 0.13

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 before 14.7.4, all versions starting from 14.8 before 14.8.2. An unauthorised user was able to steal runner registration tokens through an…

  • CVE-2026-93577CriSep 24, 2026
    risk 0.64cvss 9.9epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to an integer…

  • CVE-2026-89078CriSep 24, 2026
    risk 0.64cvss 9.9epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.2 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to execute arbitrary code on the GitLab server due to a double free…

  • CVE-2023-2442HigJun 7, 2023
    risk 0.64cvss 8.7epss 0.96

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers to perform arbitrary…

  • CVE-2020-10980CriApr 8, 2020
    risk 0.64cvss 9.8epss 0.02

    GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.

  • CVE-2019-5464CriJan 28, 2020
    risk 0.64cvss 9.8epss 0.03

    A flawed DNS rebinding protection issue was discovered in GitLab CE/EE 10.2 and later in the `url_blocker.rb` which could result in SSRF where the library is utilized.

  • CVE-2024-6385CriJul 11, 2024
    risk 0.63cvss 9.6epss 0.06

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.6, starting from 17.0 prior to 17.0.4, and starting from 17.1 prior to 17.1.2, which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2024-5655CriJun 27, 2024
    risk 0.63cvss 9.6epss 0.07

    An issue was discovered in GitLab CE/EE affecting all versions starting from 15.8 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2021-22201CriApr 2, 2021
    risk 0.63cvss 9.6epss 0.03

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.9. A specially crafted import file could read files on the server.

  • CVE-2026-19478CriAug 17, 2026
    risk 0.62cvss 9.4epss 0.60

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could allow an unauthenticated user to remotely modify or delete public projects and user…

  • CVE-2024-7102CriFeb 13, 2025
    risk 0.62cvss 9.6epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.5.0 which allows an attacker to trigger a pipeline as another user under certain circumstances.

  • CVE-2021-22242HigAug 25, 2021
    risk 0.62cvss 8.7epss 0.64

    Insufficient input sanitization in Mermaid markdown in GitLab CE/EE version 11.4 and up allows an attacker to exploit a stored cross-site scripting vulnerability via a specially-crafted markdown

  • CVE-2021-22234CriAug 5, 2021
    risk 0.62cvss 9.6epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.11 before 13.11.7, all versions starting from 13.12 before 13.12.8, and all versions starting from 14.0 before 14.0.4. A specially crafted design image allowed attackers to read arbitrary files…

  • CVE-2024-1451HigFeb 22, 2024
    risk 0.61cvss 8.7epss 0.51

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.1. A crafted payload added to the user profile page could lead to a stored XSS on the client side, allowing attackers to perform arbitrary actions on behalf of victims."

  • CVE-2022-3572CriJan 26, 2023
    risk 0.61cvss 9.3epss 0.01

    A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions from 13.5 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2. It was possible to exploit a vulnerability in setting the Jira Connect integration which could lead to a reflected…

Page 1 of 31