VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,479 total · sorted by risk
  • CVE-2025-11989LowOct 27, 2025
    risk 0.24cvss 3.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.6.0 before 18.3.5, 18.4 before 18.4.3, and 18.5 before 18.5.1 that could have allowed an authenticated attacker to execute unauthorized quick actions by including malicious commands in specific…

  • CVE-2025-5982LowJun 12, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypass IP access restrictions and view sensitive information.

  • CVE-2025-2469LowApr 10, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.9.6, and 17.10 before 17.10.4. The runtime profiling data of a specific service was accessible to unauthenticated users.

  • CVE-2024-9773LowMar 27, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 14.9 before 17.8.6, all versions starting from 17.9 before 17.8.3, all versions starting from 17.10 before 17.10.1. An input validation issue in the Harbor registry integration could have allowed a…

  • CVE-2024-8402LowMar 13, 2025
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in GitLab EE affecting all versions starting from 17.2 before 17.7.7, all versions starting from 17.8 before 17.8.5, all versions starting from 17.9 before 17.9.2. An input validation issue in the Google Cloud IAM integration feature could have enabled a…

  • CVE-2023-5117LowDec 25, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue was discovered in GitLab CE/EE affecting all versions before 17.6.0 in which users were unaware that files uploaded to comments on confidential issues and epics of public projects could be accessed without authentication via a direct link to the uploaded file URL.

  • CVE-2024-9596LowOct 10, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 16.6 prior to 17.2.9, from 17.3 prior to 17.3.5, and from 17.4 prior to 17.4.2. It was possible for an unauthenticated attacker to determine the GitLab version number for a GitLab instance.

  • CVE-2023-3509LowFeb 21, 2024
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab affecting all versions before 16.7.6, all versions starting from 16.8 before 16.8.3, all versions starting from 16.9 before 16.9.1. It was possible for group members with sub-maintainer role to change the title of privately accessible…

  • CVE-2023-5831LowNov 6, 2023
    risk 0.24cvss 3.7epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, and all versions starting from 16.5.0 before 16.5.1 which have the `super_sidebar_logged_out` feature flag enabled. Affected…

  • CVE-2023-0450LowApr 5, 2023
    risk 0.24cvss 3.7epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 8.1 to 15.8.5, and from 15.9 to 15.9.4, and from 15.10 to 15.10.1. It was possible to add a branch with an ambiguous name that could be used to social engineer users.

  • CVE-2022-3031LowOct 17, 2022
    risk 0.24cvss 3.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. It may be possible for an attacker to guess a user's password by brute force by sending crafted…

  • CVE-2021-39941LowDec 13, 2021
    risk 0.24cvss 3.7epss 0.01

    An information disclosure vulnerability in GitLab CE/EE versions 12.0 to 14.3.6, 14.4 to 14.4.4, and 14.5 to 14.5.2 allowed non-project members to see the default branch name for projects that restrict access to the repository to project members

  • CVE-2021-39898LowNov 5, 2021
    risk 0.24cvss 3.7epss 0.01

    In all versions of GitLab CE/EE since version 10.6, a project export leaks the external webhook token value which may allow access to the project which it was exported from.

  • CVE-2020-13352LowNov 17, 2020
    risk 0.24cvss 3.7epss 0.01

    Private group info is leaked leaked in GitLab CE/EE version 10.2 and above, when the project is moved from private to public group. Affected versions are: >=10.2, <13.3.9,>=13.4, <13.4.5,>=13.5, <13.5.2.

  • CVE-2020-13315LowSep 14, 2020
    risk 0.24cvss 3.7epss 0.02

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. The profile activity page was not restricting the amount of results one could request, potentially resulting in a denial of service.

  • CVE-2020-13306LowSep 14, 2020
    risk 0.24cvss 3.7epss 0.02

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Webhook feature could be abused to perform denial of service attacks due to the lack of rate limitation.

  • CVE-2020-13314LowSep 14, 2020
    risk 0.24cvss 3.7epss 0.01

    A vulnerability was discovered in GitLab versions before 13.1.10, 13.2.8 and 13.3.4. GitLab Omniauth endpoint allowed a malicious user to submit content to be displayed back to the user within error messages.

  • CVE-2019-9219LowApr 17, 2019
    risk 0.24cvss 3.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It has Incorrect Access Control (issue 2 of 5).

  • CVE-2019-9179LowApr 17, 2019
    risk 0.24cvss 3.7epss 0.02

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 5 of 5).

  • CVE-2019-9171LowApr 17, 2019
    risk 0.24cvss 3.7epss 0.01

    An issue was discovered in GitLab Community and Enterprise Edition before 11.6.10, 11.7.x before 11.7.6, and 11.8.x before 11.8.1. It allows Information Exposure (issue 1 of 5).

  • CVE-2026-7487LowAug 26, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.1 before 19.1.7, 19.2 before 19.2.5, and 19.3 before 19.3.1 that, under certain conditions, an authenticated user with reporter-role permissions who authored a merge request could have reset merge request…

  • CVE-2026-7471LowMay 14, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.9.7, 18.10 before 18.10.6, and 18.11 before 18.11.3 that could have allowed an authenticated user with control of a virtual registry upstream to make requests to internal hosts due to improper…

  • CVE-2026-3254LowApr 22, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.11 before 18.11.1 that under certain conditions could have allowed an authenticated user to load unauthorized content into another user's browser due to improper input validation in the Mermaid sandbox.

  • CVE-2025-12704LowMar 11, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.2 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user to access Virtual Registry data in groups where they are not members due to improper authorization…

  • CVE-2026-1282LowFeb 11, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that could have allowed an authenticated user to inject malicious content into project labels titles.

  • CVE-2025-14594LowFeb 11, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.6.6, 18.7 before 18.7.4, and 18.8 before 18.8.4 that, under certain conditions could have allowed an authenticated user to view certain pipeline values by querying the API.

  • CVE-2025-3950LowJan 9, 2026
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass asset proxy protection.

  • CVE-2025-12734LowDec 11, 2025
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious…

  • CVE-2025-12983LowNov 15, 2025
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.9 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to cause a denial of service condition by submitting specially crafted markdown content…

  • CVE-2025-6945LowNov 15, 2025
    risk 0.23cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.8 before 18.3.6, 18.4 before 18.4.4, and 18.5 before 18.5.2 that could have allowed an authenticated attacker to leak sensitive information from confidential issues by injecting hidden prompts into merge…

  • CVE-2025-5069LowSep 26, 2025
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.10 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to gain unauthorized access to confidential issues by creating a project with an identical name…

  • CVE-2025-10868LowSep 26, 2025
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 17.4 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 where certain string conversion methods exhibit performance degradation with large inputs.

  • CVE-2025-10867LowSep 26, 2025
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.2.7, 18.3 before 18.3.3, and 18.4 before 18.4.1 that could have allowed an authenticated user to create a denial-of-service condition by exploiting an unprotected GraphQL API through repeated…

  • CVE-2024-9163LowMay 23, 2025
    risk 0.23cvss 3.5epss 0.00

    A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a branch name confusion in confidential MRs.

  • CVE-2023-2030LowJan 12, 2024
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all versions from 12.2 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 prior to 16.7.2 in which an attacker could potentially modify the metadata of signed commits.

  • CVE-2023-4700LowNov 6, 2023
    risk 0.23cvss 3.5epss 0.00

    An authorization issue affecting GitLab EE affecting all versions from 14.7 prior to 16.3.6, 16.4 prior to 16.4.2, and 16.5 prior to 16.5.1, allowed a user to run jobs in protected environments, bypassing any required approvals.

  • CVE-2023-3906LowSep 29, 2023
    risk 0.23cvss 3.5epss 0.00

    An input validation issue in the asset proxy in GitLab EE, affecting all versions from 12.3 prior to 16.2.8, 16.3 prior to 16.3.5, and 16.4 prior to 16.4.1, allowed an authenticated attacker to craft image urls which bypass the asset proxy.

  • CVE-2023-0120LowSep 1, 2023
    risk 0.23cvss 3.5epss 0.00

    An issue has been discovered in GitLab affecting all versions starting from 10.0 before 16.1.5, all versions starting from 16.2 before 16.2.5, all versions starting from 16.3 before 16.3.1. Due to improper permission validation it was possible to edit labels description by an…

  • CVE-2023-1936LowJul 11, 2023
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.7 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1, which allows an attacker to leak the email address of a user who created a…

  • CVE-2022-4201LowJan 27, 2023
    risk 0.23cvss 3.5epss 0.01

    A blind SSRF in GitLab CE/EE affecting all from 11.3 prior to 15.4.6, 15.5 prior to 15.5.5, and 15.6 prior to 15.6.1 allows an attacker to connect to local addresses when configuring a malicious GitLab Runner.

  • CVE-2022-3819LowNov 10, 2022
    risk 0.23cvss 3.5epss 0.00

    An improper authorization issue in GitLab CE/EE affecting all versions from 15.0 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows a malicious users to set emojis on internal notes they don't have access to.

  • CVE-2022-3280LowNov 9, 2022
    risk 0.23cvss 3.5epss 0.01

    An open redirect in GitLab CE/EE affecting all versions from 10.1 prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prior to 15.5.2 allows an attacker to trick users into visiting a trustworthy URL and being redirected to arbitrary content.

  • CVE-2022-3331LowOct 17, 2022
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 14.5 before 15.1.6, all versions starting from 15.2 before 15.2.4, all versions starting from 15.3 before 15.3.2. GitLab's Zentao integration has an insecure direct object reference vulnerability that…

  • CVE-2022-3293LowOct 17, 2022
    risk 0.23cvss 3.5epss 0.01

    Email addresses were leaked in WebHook logs in GitLab EE affecting all versions from 9.3 prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1

  • CVE-2022-3288LowOct 17, 2022
    risk 0.23cvss 3.5epss 0.01

    A branch/tag name confusion in GitLab CE/EE affecting all versions prior to 15.2.5, 15.3 prior to 15.3.4, and 15.4 prior to 15.4.1 allows an attacker to manipulate pages where the content of the default branch would be expected.

  • CVE-2022-2499LowAug 5, 2022
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab EE affecting all versions starting from 13.10 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab's Jira integration has an insecure direct object reference vulnerability that…

  • CVE-2022-2307LowAug 5, 2022
    risk 0.23cvss 3.5epss 0.01

    A lack of cascading deletes in GitLab CE/EE affecting all versions starting from 13.0 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1 allows a malicious Group Owner to retain a usable Group Access Token even after the…

  • CVE-2022-2270LowJul 1, 2022
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.4 before 14.10.5, all versions starting from 15.0 before 15.0.4, all versions starting from 15.1 before 15.1.1. GitLab was leaking Conan packages names due to incorrect permissions verification.

  • CVE-2022-0489LowApr 1, 2022
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with 8.15 . It was possible to trigger a DOS by using the math feature with a specific formula in issue comments.

  • CVE-2022-0488LowMar 28, 2022
    risk 0.23cvss 3.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting with version 8.10. It was possible to trigger a timeout on a page with markdown by using a specific amount of block-quotes.

Page 26 of 30