VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,455)

  • CVE-2021-22224HigJul 7, 2021
    risk 0.46cvss 7.1epss 0.01

    A cross-site request forgery vulnerability in the GraphQL API in GitLab since version 13.12 and before versions 13.12.6 and 14.0.2 allowed an attacker to call mutations as the victim

  • CVE-2021-22214MedJun 8, 2021
    risk 0.46cvss 6.8epss 0.28

    When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab CE/EE affecting all versions starting from 10.5 was possible to exploit for an unauthenticated attacker even on a GitLab instance where registration is limited

  • CVE-2020-26405HigNov 17, 2020
    risk 0.46cvss 7.1epss 0.01

    Path traversal vulnerability in package upload functionality in GitLab CE/EE starting from 12.8 allows an attacker to save packages in arbitrary locations. Affected versions are >=12.8, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-13325HigSep 30, 2020
    risk 0.46cvss 7.1epss 0.01

    A vulnerability was discovered in GitLab versions prior 13.1. The comment section of the issue page was not restricting the characters properly, potentially resulting in a denial of service.

  • CVE-2020-13303HigSep 15, 2020
    risk 0.46cvss 7.1epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. Due to improper verification of permissions, an unauthorized user can access a private repository within a public project.

  • CVE-2018-19585HigMay 17, 2019
    risk 0.46cvss 7.5epss 0.13

    GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

  • CVE-2025-13761HigJan 9, 2026
    risk 0.45cvss 8.0epss 0.01

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by convincing the legitimate user to…

  • CVE-2024-8124HigSep 12, 2024
    risk 0.45cvss 7.5epss 0.40

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.

  • CVE-2024-2651MedMay 14, 2024
    risk 0.45cvss 6.5epss 0.33

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown…

  • CVE-2024-2454MedMay 14, 2024
    risk 0.45cvss 6.5epss 0.33

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 prior to 16.9.7, starting from 16.10 prior to 16.10.5, and starting from 16.11 prior to 16.11.2. The pins endpoint is susceptible to DoS through a crafted request.

  • CVE-2026-1322MedMay 14, 2026
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.0 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with a read_api scoped OAuth application to create issues and add comments to issues in…

  • CVE-2026-2745MedMar 25, 2026
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 7.11 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to bypass WebAuthn two-factor authentication and gain unauthorized access to user accounts…

  • CVE-2026-1724MedMar 25, 2026
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to access API tokens of self-hosted AI models due to improper access control.

  • CVE-2025-11984MedDec 11, 2025
    risk 0.44cvss 6.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain…

  • CVE-2024-12303MedAug 13, 2025
    risk 0.44cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including…

  • CVE-2024-12093MedMay 22, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 11.1 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. Improper XPath validation allows modified SAML response to bypass 2FA requirement under specialized conditions.

  • CVE-2025-0549MedMay 9, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 17.3 prior to 17.9.8, from 17.10 prior to 17.10.6, and from 17.11 prior to 17.11.2. A security vulnerability allows attackers to bypass Device OAuth flow protections, enabling authorization form…

  • CVE-2024-12570MedDec 12, 2024
    risk 0.44cvss 6.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 prior to 17.4.6, from 17.5 prior to 17.5.4, and from 17.6 prior to 17.6.2. It may have been possible for an attacker with a victim's `CI_JOB_TOKEN` to obtain a GitLab session token belonging…

  • CVE-2024-7404MedNov 14, 2024
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in GitLab CE/EE affecting all versions starting from 17.2 prior to 17.3.7, starting from 17.4 prior to 17.4.4 and starting from 17.5 prior to 17.5.2, which could have allowed an attacker gaining full API access as the victim via the Device OAuth flow.

  • CVE-2024-2177MedJul 9, 2024
    risk 0.44cvss 6.8epss 0.01

    A Cross Window Forgery vulnerability exists within GitLab CE/EE affecting all versions from 16.3 prior to 16.11.5, 17.0 prior to 17.0.3, and 17.1 prior to 17.1.1. This condition allows for an attacker to abuse the OAuth authentication flow via a crafted payload.

Page 18 of 73