VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (585)

  • CVE-2024-8312HigOct 24, 2024
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 17.3.6, 17.4 before 17.4.3, and 17.5 before 17.5.1. An attacker could inject HTML into the Global Search field on a diff view leading to XSS.

  • CVE-2024-2434HigApr 25, 2024
    risk 0.57cvss 8.5epss 0.23

    An issue has been discovered in GitLab affecting all versions of GitLab CE/EE 16.9 prior to 16.9.6, 16.10 prior to 16.10.4, and 16.11 prior to 16.11.1 where path traversal could lead to DoS and restricted file read.

  • CVE-2024-2279HigApr 12, 2024
    risk 0.57cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a…

  • CVE-2023-6371HigMar 28, 2024
    risk 0.57cvss 8.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.8.5, all versions starting from 16.9 before 16.9.3, all versions starting from 16.10 before 16.10.1. A wiki page with a crafted payload may lead to a Stored XSS, allowing attackers to perform arbitrary…

  • CVE-2022-2230HigJul 1, 2022
    risk 0.57cvss 8.1epss 0.56

    A Stored Cross-Site Scripting vulnerability in the project settings page in GitLab CE/EE affecting all versions from 14.4 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1, allows an attacker to execute arbitrary JavaScript code in GitLab on a victim's behalf.

  • CVE-2022-1190HigApr 4, 2022
    risk 0.57cvss 8.7epss 0.87

    Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attacker to exploit a stored XSS by abusing multi-word milestone references in issue descriptions, comments, etc.

  • CVE-2021-39946HigJan 18, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

  • CVE-2021-22241HigAug 5, 2021
    risk 0.57cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

  • CVE-2021-22213HigJun 8, 2021
    risk 0.57cvss 8.8epss 0.02

    A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

  • CVE-2019-5462HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.03

    A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

  • CVE-2019-5486HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.02

    A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

  • CVE-2018-19569HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.02

    GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

  • CVE-2025-5121HigJun 20, 2025
    risk 0.56cvss 8.5epss 0.10

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

  • CVE-2022-0244HigJan 18, 2022
    risk 0.56cvss 8.6epss 0.02

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

  • CVE-2026-15423HigAug 12, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.0 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute CI/CD pipelines on a…

  • CVE-2026-5173HigApr 8, 2026
    risk 0.55cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9.6 before 18.8.9, 18.9 before 18.9.5, and 18.10 before 18.10.3 that could have allowed an authenticated user to invoke unintended server-side methods through websocket connections due to improper…

  • CVE-2025-6454HigSep 12, 2025
    risk 0.55cvss 8.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 16.11 before 18.1.6, 18.2 before 18.2.6, and 18.3 before 18.3.2 that could have allowed authenticated users to make unintended internal requests through proxy environments by injecting crafted sequences.

  • CVE-2024-9693HigNov 14, 2024
    risk 0.55cvss 8.5epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.0 prior to 17.3.7, starting from 17.4 prior to 17.4.4, and starting from 17.5 prior to 17.5.2, which could have allowed unauthorized access to the Kubernetes agent in a cluster under specific…

  • CVE-2022-2497HigAug 5, 2022
    risk 0.55cvss 8.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. A malicious developer could exfiltrate an integration's access token by modifying…

  • CVE-2018-19571HigJul 10, 2019
    risk 0.55cvss 7.7epss 0.28

    GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

Page 3 of 30