VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2021-22184MedMar 26, 2021
    risk 0.40cvss 6.2epss 0.00

    An information disclosure issue in GitLab starting from version 12.8 allowed a user with access to the server logs to see sensitive information that wasn't properly redacted.

  • CVE-2020-13262MedJun 19, 2020
    risk 0.40cvss 6.1epss 0.01

    Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link

  • CVE-2020-13271MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1

  • CVE-2020-13269MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1

  • CVE-2020-13267MedJun 10, 2020
    risk 0.40cvss 6.1epss 0.02

    A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1

  • CVE-2020-10076MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.

  • CVE-2020-10075MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

  • CVE-2020-10092MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.

  • CVE-2020-10091MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.

  • CVE-2020-10078MedMar 13, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

  • CVE-2019-12444MedMar 10, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.9 through 11.11. Wiki Pages contained a lack of input validation which resulted in a persistent XSS vulnerability.

  • CVE-2019-12442MedMar 10, 2020
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Enterprise Edition 11.7 through 11.11. The epic details page contained a lack of input validation and output encoding issue which resulted in a persistent XSS vulnerability on child epics.

  • CVE-2020-7973MedFeb 5, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab through 12.7.2 allows XSS.

  • CVE-2020-7971MedFeb 5, 2020
    risk 0.40cvss 6.1epss 0.01

    GitLab EE 11.0 and later through 12.7.2 allows XSS.

  • CVE-2019-15586MedJan 28, 2020
    risk 0.40cvss 6.1epss 0.01

    A XSS exists in Gitlab CE/EE < 12.1.10 in the Mermaid plugin.

  • CVE-2019-18454MedNov 26, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.5 through 12.4 in link validation for RDoc wiki pages feature. It has XSS.

  • CVE-2019-18451MedNov 26, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 10.7.4 through 12.4 in the InternalRedirect filtering feature. It has an Open Redirect.

  • CVE-2019-15739MedSep 16, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 8.1 through 12.2.1. Certain areas displaying Markdown were not properly sanitizing some XSS payloads.

  • CVE-2019-15724MedSep 16, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.

  • CVE-2019-11547MedSep 9, 2019
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.8.9, 11.9.x before 11.9.10, and 11.10.x before 11.10.2. It has Improper Encoding or Escaping of Output. The branch name on new merge request notification emails isn't escaped, which could potentially…

  • CVE-2018-19493MedJul 10, 2019
    risk 0.40cvss 6.1epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1. There is a persistent XSS vulnerability in the environment pages due to a lack of input validation and output encoding.

  • CVE-2019-10117MedMay 16, 2019
    risk 0.40cvss 6.1epss 0.02

    An Open Redirect issue was discovered in GitLab Community and Enterprise Edition before 11.7.8, 11.8.x before 11.8.4, and 11.9.x before 11.9.2. A redirect is triggered after successful authentication within the Oauth/:GeoAuthController for the secondary Geo node.

  • CVE-2018-18643MedApr 25, 2019
    risk 0.40cvss 6.1epss 0.01

    GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

  • CVE-2018-18642MedDec 4, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.

  • CVE-2018-16050MedOct 3, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition 11.1.x before 11.1.5 and 11.2.x before 11.2.2. There is Persistent XSS in the Merge Request Changes View.

  • CVE-2018-10379MedMay 31, 2018
    risk 0.40cvss 6.1epss 0.01

    An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS vulnerability.

  • CVE-2018-9244MedApr 5, 2018
    risk 0.40cvss 6.1epss 0.01

    GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3,…

  • CVE-2018-9243MedApr 5, 2018
    risk 0.40cvss 6.1epss 0.01

    GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and…

  • CVE-2017-0924MedMar 21, 2018
    risk 0.40cvss 6.1epss 0.01

    Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the labels component resulting in persistent cross site scripting.

  • CVE-2017-0923MedMar 21, 2018
    risk 0.40cvss 6.1epss 0.01

    Gitlab Community Edition version 9.1 is vulnerable to lack of input validation in the IPython notebooks component resulting in persistent cross site scripting.

  • CVE-2017-0917MedMar 21, 2018
    risk 0.40cvss 6.1epss 0.02

    Gitlab Community Edition version 10.2.4 is vulnerable to lack of input validation in the CI job component resulting in persistent cross site scripting.

  • CVE-2017-8778MedMay 4, 2017
    risk 0.40cvss 6.1epss 0.01

    GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.

  • CVE-2025-13772HigJan 9, 2026
    risk 0.39cvss 7.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces by manipulating namespace…

  • CVE-2021-39895MedNov 5, 2021
    risk 0.39cvss 6.0epss 0.01

    In all versions of GitLab CE/EE since version 8.0, an attacker can set the pipeline schedules to be active in a project export so when an unsuspecting owner imports that project, pipelines are active by default on that project. Under specialized conditions, this may lead to…

  • CVE-2020-13327MedOct 22, 2020
    risk 0.39cvss 6.0epss 0.01

    An issue has been discovered in GitLab Runner affecting all versions starting from 13.4.0 before 13.4.2, all versions starting from 13.3.0 before 13.3.7, all versions starting from 13.2.0 before 13.2.10. Insecure Runner Configuration in Kubernetes Environments

  • CVE-2019-16170HigSep 16, 2019
    risk 0.39cvss 7.1epss 0.01

    An issue was discovered in GitLab Enterprise Edition 11.x and 12.x before 12.0.9, 12.1.x before 12.1.9, and 12.2.x before 12.2.5. It has Incorrect Access Control.

  • CVE-2019-6793HigSep 9, 2019
    risk 0.39cvss 7.0epss 0.04

    An issue was discovered in GitLab Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. The Jira integration feature is vulnerable to an unauthenticated blind SSRF issue.

  • CVE-2026-3160MedMay 14, 2026
    risk 0.38cvss 5.8epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.7 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user to view Jira issues outside the configured project scope due to an integration filter…

  • CVE-2025-2246MedAug 27, 2025
    risk 0.38cvss 5.8epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that could have allowed unauthenticated users to access sensitive manual CI/CD variables by querying the GraphQL API.

  • CVE-2023-5612MedJan 26, 2024
    risk 0.38cvss 5.3epss 0.05

    An issue has been discovered in GitLab affecting all versions before 16.6.6, 16.7 prior to 16.7.4, and 16.8 prior to 16.8.1. It was possible to read the user email address via tags feed although the visibility in the user profile has been disabled.

  • CVE-2023-5332MedDec 4, 2023
    risk 0.38cvss 5.9epss 0.01

    Patch in third party library Consul requires 'enable-script-checks' to be set to False. This was required to enable a patch by the vendor. Without this setting the patch could be bypassed. This only affects GitLab-EE.

  • CVE-2023-2589MedJun 7, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. An attacker can clone a repository from a public project, from a disallowed IP,…

  • CVE-2019-14942MedApr 16, 2023
    risk 0.38cvss 5.9epss 0.00

    An issue was discovered in GitLab Community and Enterprise Edition before 11.11.8, 12 before 12.0.6, and 12.1 before 12.1.6. Cookies for GitLab Pages (which have access control) could be sent over cleartext HTTP.

  • CVE-2023-1733MedApr 5, 2023
    risk 0.38cvss 5.8epss 0.01

    A denial of service condition exists in the Prometheus server bundled with GitLab affecting all versions from 11.10 to 15.8.5, 15.9 to 15.9.4 and 15.10 to 15.10.1.

  • CVE-2023-1098MedApr 5, 2023
    risk 0.38cvss 5.8epss 0.01

    An information disclosure vulnerability has been discovered in GitLab EE/CE affecting all versions starting from 11.5 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1 will allow an admin to leak password from…

  • CVE-2023-0319MedApr 5, 2023
    risk 0.38cvss 5.8epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 13.6 before 15.8.5, all versions starting from 15.9 before 15.9.4, all versions starting from 15.10 before 15.10.1, allowing to read environment names supposed to be restricted to project memebers only.

  • CVE-2022-3613MedJan 12, 2023
    risk 0.38cvss 5.8epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. A crafted Prometheus Server query can cause high resource consumption and may lead to Denial of…

  • CVE-2022-2501MedAug 5, 2022
    risk 0.38cvss 5.9epss 0.01

    An improper access control issue in GitLab EE affecting all versions from 12.0 prior to 15.0.5, 15.1 prior to 15.1.4, and 15.2 prior to 15.2.1 allows an attacker to bypass IP allow-listing and download artifacts. This attack only bypasses IP allow-listing, proper permissions are…

  • CVE-2022-0123MedMar 28, 2022
    risk 0.38cvss 5.9epss 0.00

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab does not validate SSL certificates for some of external CI services which makes it possible to perform MitM attacks on connections to these…

  • CVE-2021-39937MedDec 13, 2021
    risk 0.38cvss 5.9epss 0.01

    A collision in access memoization logic in all versions of GitLab CE/EE before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2, leads to potential elevated privileges in groups and projects under rare circumstances

Page 13 of 30