VYPR

GitLab EE and CE

by GitLab Inc.

Source repositories

CVEs (585)

  • CVE-2020-13276HigJun 19, 2020
    risk 0.48cvss 7.4epss 0.01

    User is allowed to set an email as a notification email even without verifying the new email in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2026-13320HigJul 8, 2026
    risk 0.47cvss 7.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.7 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to execute arbitrary scripts in another user's browser session due to…

  • CVE-2026-0595HigFeb 11, 2026
    risk 0.47cvss 7.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.9 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to add unauthorized email addresses to victim accounts through HTML…

  • CVE-2025-14560HigFeb 11, 2026
    risk 0.47cvss 7.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by…

  • CVE-2026-19650HigAug 17, 2026
    risk 0.46cvss 7.1epss

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4 that under certain conditions could have allowed an unauthenticated user to execute mutations via GET requests due to…

  • CVE-2021-39944HigDec 13, 2021
    risk 0.46cvss 7.1epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.0 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A permissions validation flaw allowed group members with a developer role to…

  • CVE-2018-19585HigMay 17, 2019
    risk 0.46cvss 7.5epss 0.15

    GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

  • CVE-2025-13761HigJan 9, 2026
    risk 0.45cvss 8.0epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to…

  • CVE-2024-2454MedMay 14, 2024
    risk 0.45cvss 6.5epss 0.33

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

  • CVE-2026-1322MedMay 14, 2026
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in…

  • CVE-2026-2745MedMar 25, 2026
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts…

  • CVE-2025-11984MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain…

  • CVE-2024-12303MedAug 13, 2025
    risk 0.44cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including…

  • CVE-2024-12093MedMay 22, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

  • CVE-2025-0549MedMay 9, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form…

  • CVE-2024-12570MedDec 12, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging…

  • CVE-2024-7404MedNov 14, 2024
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

  • CVE-2024-2177MedJul 9, 2024
    risk 0.44cvss 6.8epss 0.01

    A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

  • CVE-2024-5430MedJun 27, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.10 prior to 16.11.5, starting from 17.0 prior to 17.0.3, and starting from 17.1 prior to 17.1.1, which allows a project maintainer can delete the merge request approval policy via graphQL.

  • CVE-2022-3018MedOct 28, 2022
    risk 0.44cvss 6.8epss 0.01

    An information disclosure vulnerability in GitLab CE/EE affecting all versions starting from 9.3 before 15.2.5, all versions starting from 15.3 before 15.3.4, all versions starting from 15.4 before 15.4.1 allows a project maintainer to access the DataDog integration API key from…

Page 8 of 30