VYPR

GitLab

by GitLab Inc.

Source repositories

CVEs (1,433)

  • CVE-2021-39946HigJan 18, 2022
    risk 0.57cvss 8.7epss 0.01

    Improper neutralization of user input in GitLab CE/EE versions 14.3 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed an attacker to exploit XSS by abusing the generation of the HTML code related to emojis

  • CVE-2021-39885HigOct 4, 2021
    risk 0.57cvss 8.7epss 0.01

    A Stored XSS in merge request creation page in all versions of Gitlab EE starting from 13.7 before 14.1.7, all versions starting from 14.2 before 14.2.5, and all versions starting from 14.3 before 14.3.1 allows an attacker to execute arbitrary JavaScript code on the victim's…

  • CVE-2021-22241HigAug 5, 2021
    risk 0.57cvss 8.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 14.0. It was possible to exploit a stored cross-site-scripting via a specifically crafted default branch name.

  • CVE-2021-22213HigJun 8, 2021
    risk 0.57cvss 8.8epss 0.02

    A cross-site leak vulnerability in the OAuth flow of all versions of GitLab CE/EE since 7.10 allowed an attacker to leak an OAuth access token by getting the victim to visit a malicious page with Safari

  • CVE-2019-12430HigMar 10, 2020
    risk 0.57cvss 8.8epss 0.03

    An issue was discovered in GitLab Community and Enterprise Edition 11.11. A specially crafted payload would allow an authenticated malicious user to execute commands remotely through the repository download feature. It allows Command Injection.

  • CVE-2013-4583HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.02

    The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated users to gain privileges and clone arbitrary repositories.

  • CVE-2019-5468HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.02

    An privilege escalation issue was discovered in Gitlab versions < 12.1.2, < 12.0.4, and < 11.11.6 when Mattermost slash commands are used with a blocked account.

  • CVE-2019-5462HigJan 28, 2020
    risk 0.57cvss 8.8epss 0.03

    A privilege escalation issue was discovered in GitLab CE/EE 9.0 and later when trigger tokens are not rotated once ownership of them has changed.

  • CVE-2019-19261HigJan 3, 2020
    risk 0.57cvss 8.8epss 0.01

    GitLab Enterprise Edition (EE) 6.7 and later through 12.5 allows SSRF.

  • CVE-2019-5486HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.02

    A authentication bypass vulnerability exists in GitLab CE/EE <v12.3.2, <v12.2.6, and <v12.1.10 in the Salesforce login integration that could be used by an attacker to create an account that bypassed domain restrictions and email verification requirements.

  • CVE-2019-15589HigDec 18, 2019
    risk 0.57cvss 8.8epss 0.01

    An improper access control vulnerability exists in Gitlab <v12.3.2, <v12.2.6, <v12.1.12 which would allow a blocked user would be able to use GIT clone and pull if he had obtained a CI/CD token before.

  • CVE-2019-18457HigNov 26, 2019
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.8 through 12.4 when handling Security tokens.. It has Insecure Permissions.

  • CVE-2019-6960CriSep 9, 2019
    risk 0.57cvss 9.8epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 9.x, 10.x, and 11.x before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It has Incorrect Access Control. Access to the internal wiki is permitted when an external wiki service is enabled.

  • CVE-2018-19569HigJul 10, 2019
    risk 0.57cvss 8.8epss 0.02

    GitLab CE/EE, versions 8.8 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an authorization vulnerability that allows access to the web-UI as a user using a Personal Access Token of any scope.

  • CVE-2018-19359HigApr 25, 2019
    risk 0.57cvss 8.8epss 0.02

    GitLab Community and Enterprise Edition 8.9 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 has Incorrect Access Control.

  • CVE-2018-18646HigDec 4, 2018
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows SSRF.

  • CVE-2017-0926HigMar 21, 2018
    risk 0.57cvss 8.8epss 0.01

    Gitlab Community Edition version 10.3 is vulnerable to an improper authorization issue in the Oauth sign-in component resulting in unauthorized user login.

  • CVE-2017-12426HigAug 14, 2017
    risk 0.57cvss 8.8epss 0.04

    GitLab Community Edition (CE) and Enterprise Edition (EE) before 8.17.8, 9.0.x before 9.0.13, 9.1.x before 9.1.10, 9.2.x before 9.2.10, 9.3.x before 9.3.10, and 9.4.x before 9.4.4 might allow remote attackers to execute arbitrary code via a crafted SSH URL in a project import.

  • CVE-2025-5121HigJun 20, 2025
    risk 0.56cvss 8.5epss 0.10

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance frameworks to be applied to projects outside the compliance framework's group.

  • CVE-2022-0244HigJan 18, 2022
    risk 0.56cvss 8.6epss 0.02

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 14.5. Arbitrary file read was possible by importing a group was due to incorrect handling of file.

Page 6 of 72