VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,455)

  • CVE-2024-9183HigDec 5, 2025
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 prior to 18.4.5, 18.5 prior to 18.5.3, and 18.6 prior to 18.6.1 that could have allowed an authenticated user to obtain credentials from higher-privileged users and perform actions in their context…

  • CVE-2025-11340HigOct 9, 2025
    risk 0.50cvss 7.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.3 to 18.3.4, 18.4 to 18.4.2 that, under certain conditions, could have allowed authenticated users with read-only API tokens to perform unauthorized write operations on vulnerability records by exploiting…

  • CVE-2025-9958HigSep 26, 2025
    risk 0.50cvss 7.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 14.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1, that could have allowed Guest users to access sensitive information stored in virtual registry configurations.

  • CVE-2025-4439HigJul 23, 2025
    risk 0.50cvss 7.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content…

  • CVE-2025-1908HigApr 24, 2025
    risk 0.50cvss 7.7epss 0.00

    An issue has been discovered in GitLab EE/CE that could allow an attacker to track users' browsing activities, potentially leading to full account take-over, affecting all versions from 16.6 before 17.9.7, 17.10 before 17.10.5, and 17.11 before 17.11.1.

  • CVE-2025-0555HigMar 3, 2025
    risk 0.50cvss 7.7epss 0.00

    A Cross Site Scripting (XSS) vulnerability in GitLab-EE affecting all versions from 16.6 prior to 17.7.6, 17.8 prior to 17.8.4, and 17.9 prior to 17.9.1 allows an attacker to bypass security controls and execute arbitrary scripts in a users browser under specific conditions.

  • CVE-2024-7047HigJul 25, 2024
    risk 0.50cvss 7.7epss 0.00

    A cross site scripting vulnerability exists in GitLab CE/EE affecting all versions from 16.6 prior to 17.0.5, 17.1 prior to 17.1.3, 17.2 prior to 17.2.1 allowing an attacker to execute arbitrary scripts under the context of the current logged in user.

  • CVE-2024-3092HigApr 12, 2024
    risk 0.50cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of…

  • CVE-2024-0199HigMar 7, 2024
    risk 0.50cvss 7.7epss 0.01

    An authorization bypass vulnerability was discovered in GitLab affecting versions 11.3 prior to 16.7.7, 16.7.6 prior to 16.8.4, and 16.8.3 prior to 16.9.2. An attacker could bypass CODEOWNERS by utilizing a crafted payload in an old feature branch to perform malicious actions.

  • CVE-2024-0410HigFeb 22, 2024
    risk 0.50cvss 7.7epss 0.00

    An authorization bypass vulnerability was discovered in GitLab affecting versions 15.1 prior to 16.7.6, 16.8 prior to 16.8.3, and 16.9 prior to 16.9.1. A developer could bypass CODEOWNERS approvals by creating a merge conflict.

  • CVE-2022-3767HigMar 9, 2023
    risk 0.50cvss 7.7epss 0.01

    Missing validation in DAST analyzer affecting all versions from 1.11.0 prior to 3.0.32, allows custom request headers to be sent with every request, regardless of the host.

  • CVE-2022-0427HigMar 28, 2022
    risk 0.50cvss 7.7epss 0.01

    Missing sanitization of HTML attributes in Jupyter notebooks in all versions of GitLab CE/EE since version 14.5 allows an attacker to perform arbitrary HTTP POST requests on a user's behalf leading to potential account takeover

  • CVE-2021-22260HigNov 5, 2021
    risk 0.50cvss 7.7epss 0.01

    A stored Cross-Site Scripting vulnerability in the DataDog integration in all versions of GitLab CE/EE starting from 13.7 before 14.0.9, all versions starting from 14.1 before 14.1.4, and all versions starting from 14.2 before 14.2.2 allows an attacker to execute arbitrary…

  • CVE-2021-39877HigOct 4, 2021
    risk 0.50cvss 7.7epss 0.01

    A vulnerability was discovered in GitLab starting with version 12.2 that allows an attacker to cause uncontrolled resource consumption with a specially crafted file.

  • CVE-2021-22246HigAug 20, 2021
    risk 0.50cvss 7.7epss 0.01

    A vulnerability was discovered in GitLab versions before 14.0.2, 13.12.6, 13.11.6. GitLab Webhook feature could be abused to perform denial of service attacks.

  • CVE-2021-22238MedAug 20, 2021
    risk 0.50cvss 6.8epss 0.72

    An issue has been discovered in GitLab affecting all versions starting with 13.3. GitLab was vulnerable to a stored XSS by using the design feature in issues.

  • CVE-2021-22181HigJun 11, 2021
    risk 0.50cvss 7.7epss 0.01

    A denial of service vulnerability in GitLab CE/EE affecting all versions since 11.8 allows an attacker to create a recursive pipeline relationship and exhaust resources.

  • CVE-2020-13323HigSep 30, 2020
    risk 0.50cvss 7.7epss 0.01

    A vulnerability was discovered in GitLab versions prior 13.1. Under certain conditions private merge requests could be read via Todos

  • CVE-2018-14603HigJul 27, 2018
    risk 0.50cvss 8.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 10.8.7, 11.0.x before 11.0.5, and 11.1.x before 11.1.2. CSRF can occur in the Test feature of the System Hooks component.

  • CVE-2026-1168HigSep 16, 2026
    risk 0.49cvss 7.5epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4.6 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that under certain conditions could have allowed an unauthenticated user to cause denial of service due to improper resource allocation…

Page 10 of 73