VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (607)

  • CVE-2022-2417MedAug 5, 2022
    risk 0.40cvss 6.2epss 0.01

    Insufficient validation in GitLab CE/EE affecting all versions from 12.10 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an authenticated and authorised user to import a project that includes branch names which are 40 hexadecimal characters, which could…

  • CVE-2020-13262MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

  • CVE-2020-13271MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2020-13269MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

  • CVE-2020-13267MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

  • CVE-2019-15586MedJan 28, 2020
    risk 0.40cvss 6.1epss 0.01

    A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

  • CVE-2021-39895MedNov 5, 2021
    risk 0.39cvss 6.0epss 0.01

    In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to…

  • CVE-2026-3160MedMay 14, 2026
    risk 0.38cvss 5.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter…

  • CVE-2025-2246MedAug 27, 2025
    risk 0.38cvss 5.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

  • CVE-2023-1098MedApr 5, 2023
    risk 0.38cvss 5.8epss 0.01

    An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from…

  • CVE-2022-3613MedJan 12, 2023
    risk 0.38cvss 5.8epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of…

  • CVE-2021-39937MedDec 13, 2021
    risk 0.38cvss 5.9epss 0.01

    A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

  • CVE-2021-39891MedOct 5, 2021
    risk 0.38cvss 5.9epss 0.01

    In all versions of GitLab CE/EE since version 8.0, access tokens created as part of admin's impersonation of a user are not cleared at the end of impersonation which may lead to unnecessary sensitive info disclosure.

  • CVE-2021-22229MedJul 6, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.8. Under a special condition it was possible to access data of an internal repository through project fork done by a project member.

  • CVE-2021-22200MedApr 2, 2021
    risk 0.38cvss 5.9epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 12.6. Under a special condition it was possible to access data of an internal repository through a public project fork as an anonymous user.

  • CVE-2021-22189MedMar 4, 2021
    risk 0.38cvss 5.9epss 0.01

    Starting with version 13.7 the Gitlab CE/EE editions were affected by a security issue related to the validation of the certificates for the Fortinet OTP that could result in authentication issues.

  • CVE-2024-6502MedAug 22, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.2 prior to 17.1.6 starting from 17.2 prior to 17.2.4, and starting from 17.3 prior to 17.3.1, which allows an attacker to create a branch with the same name as a deleted tag.

  • CVE-2024-3035MedAug 8, 2024
    risk 0.37cvss 6.8epss 0.00

    A permission check vulnerability in GitLab CE/EE affecting all versions starting from 8.12 prior to 17.0.6, 17.1 prior to 17.1.4, and 17.2 prior to 17.2.2 allowed for LFS tokens to read and write to the user owned repositories.

  • CVE-2024-6329MedAug 8, 2024
    risk 0.37cvss 5.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 8.16 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, which causes the web interface to fail to render the diff correctly when the path is encoded.

  • CVE-2023-3444MedJul 13, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to merge arbitrary code into protected branches.

Page 14 of 31