VYPR

Vendor CVEs

GitLab Inc.

All CVEs

1,450 total · sorted by risk
  • CVE-2022-0093LowJan 18, 2022
    risk 0.16cvss 3.5epss 0.01

    An issue has been discovered affecting GitLab versions prior to 14.4.5, between 14.5.0 and 14.5.3, and between 14.6.0 and 14.6.1. GitLab allows a user with an expired password to access sensitive information through RSS feeds.

  • CVE-2021-22202LowApr 2, 2021
    risk 0.16cvss 2.4epss 0.00

    An issue has been discovered in GitLab CE/EE affecting all previous versions. If the victim is an admin, it was possible to issue a CSRF in System hooks through the API.

  • CVE-2020-13353LowNov 17, 2020
    risk 0.16cvss 2.5epss 0.00

    When importing repos via URL, one time use git credentials were persisted beyond the expected time window in Gitaly 1.79.0 or above.

  • CVE-2025-12697LowMar 11, 2026
    risk 0.14cvss 2.2epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.5 before 18.7.6, 18.8 before 18.8.6, and 18.9 before 18.9.2 that could have allowed an authenticated user with maintainer-role permissions to reveal Datadog API credentials under certain conditions.

  • CVE-2022-2534LowAug 5, 2022
    risk 0.14cvss 2.2epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 15.0.5, all versions starting from 15.1 before 15.1.4, all versions starting from 15.2 before 15.2.1. GitLab was returning contributor emails due to improper data handling in the Datadog…

  • CVE-2021-39879LowOct 4, 2021
    risk 0.14cvss 2.2epss 0.00

    Missing authentication in all versions of GitLab CE/EE since version 7.11.0 allows an attacker with access to a victim's session to disable two-factor authentication

  • CVE-2025-13611LowNov 26, 2025
    risk 0.13cvss 2.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.2 before 18.5.5 and 18.6 before 18.6.3 that could have allowed an authenticated user with access to certain logs to obtain sensitive tokens under specific conditions.

  • CVE-2023-3511LowDec 15, 2023
    risk 0.13cvss 2.0epss 0.00

    An issue has been discovered in GitLab EE affecting all versions starting from 8.17 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. It was possible for auditor users to fork and submit merge requests to private…

  • CVE-2022-1426LowMay 11, 2022
    risk 0.13cvss 2.0epss 0.01

    An issue has been discovered in GitLab affecting all versions starting from 12.6 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly authenticating a user that had some certain amount of…

  • CVE-2021-39900LowOct 4, 2021
    risk 0.13cvss 2.0epss 0.01

    Information disclosure from SendEntry in GitLab starting with 10.8 allowed exposure of full URL of artifacts stored in object-storage with a temporary availability via Rails logs.

  • CVE-2021-39911LowNov 5, 2021
    risk 0.11cvss 1.7epss 0.01

    An improper access control flaw in all versions of GitLab CE/EE starting from 13.9 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 exposes private email address of Issue and Merge Requests assignee to Webhook data…

  • CVE-2013-4490May 13, 2014
    risk 0.06cvss epss 0.42

    The SSH key upload feature (lib/gitlab_keys.rb) in gitlab-shell before 1.7.3, as used in GitLab 5.0 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands via shell metacharacters in the public key.

  • CVE-2013-7316Jan 24, 2014
    risk 0.03cvss epss 0.02

    Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.

  • CVE-2026-6336MedJul 29, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthorized user to view project import source information due to a missing…

  • CVE-2026-6267HigJul 29, 2026
    risk 0.00cvss 8.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.1.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Developer role to access unauthorized information due to…

  • CVE-2026-4672MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with guest-role permissions to access test report contents they were…

  • CVE-2026-3093MedJul 29, 2026
    risk 0.00cvss 4.7epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an attacker to execute arbitrary JavaScript in another user's browser via a crafted URL, due…

  • CVE-2026-16553MedJul 29, 2026
    risk 0.00cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed some sensitive information to be disclosed to an unintended host due to improper handling of…

  • CVE-2026-15975HigJul 29, 2026
    risk 0.00cvss 7.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to cause a denial of service due to insufficient resource throttling…

  • CVE-2026-15831MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to bypass administrator-configured tool governance policies due to improper authorization…

  • CVE-2026-15077MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.3 and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to access information from unauthorized projects due to improper neutralization of untrusted…

  • CVE-2026-14351MedJul 29, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an unauthenticated user to view the title of a confidential issue through a publicly…

  • CVE-2026-14341MedJul 29, 2026
    risk 0.00cvss 4.9epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with Maintainer role to modify protected branch configuration due to…

  • CVE-2026-13113MedJul 29, 2026
    risk 0.00cvss 6.5epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to merge code into a protected branch without the required approvals due…

  • CVE-2026-12436HigJul 29, 2026
    risk 0.00cvss 8.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.0 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user to modify CI/CD configuration belonging to another user due to…

  • CVE-2025-14562LowJul 29, 2026
    risk 0.00cvss 3.1epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.6 before 19.0.5, 19.1 before 19.1.3, and 19.2 before 19.2.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to commit changes to a project after…

  • CVE-2026-8472MedJul 8, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.9 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with minimal access permissions to read work item metadata from private…

  • CVE-2026-6896HigJul 8, 2026
    risk 0.00cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary scripts in another…

  • CVE-2025-12506LowJul 8, 2026
    risk 0.00cvss 3.5epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 16.5 before 18.11.7, 19.0 before 19.0.4, and 19.1 before 19.1.2 that under certain conditions could have allowed an authenticated user to create a repository where the content displayed in the web…

  • CVE-2026-8330MedJun 25, 2026
    risk 0.00cvss 4.4epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 9.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed sensitive information to be written to application logs due to insufficient filtering in a…

  • CVE-2026-5952MedJun 25, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.11 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to bypass package protection rules…

  • CVE-2026-5796MedJun 25, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with Reporter-level group permissions to view package metadata from…

  • CVE-2026-5309MedJun 25, 2026
    risk 0.00cvss 5.4epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to read or modify another group's virtual registry cleanup policy…

  • CVE-2026-3176LowJun 25, 2026
    risk 0.00cvss 3.1epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 18.6 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with limited permissions to access project information due to…

  • CVE-2026-2238MedJun 25, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to view confidential issue references on public projects due to…

  • CVE-2026-1606MedJun 25, 2026
    risk 0.00cvss 4.3epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.8 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user to conceal content within a Snippet due to improper input validation.

  • CVE-2026-12635NonJun 25, 2026
    risk 0.00cvss 0.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with maintainer-role permissions to make requests to internal network…

  • CVE-2026-12053HigJun 25, 2026
    risk 0.00cvss 8.6epss 0.01

    GitLab has remediated an issue in GitLab EE affecting all versions from 19.1 before 19.1.1 that under certain conditions could have allowed a user to access sensitive information that had already been committed to a project, due to insufficient output filtering in Duo Workflows.

  • CVE-2026-11379MedJun 25, 2026
    risk 0.00cvss 5.3epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 13.11 prior to 18.11.6, 19.0 prior to 19.0.3, and 19.1 prior to 19.1.1 in which incorrect authorization in DAST site profile management could allow a user with Developer role to exfiltrate DAST site profile…

  • CVE-2026-10712HigJun 25, 2026
    risk 0.00cvss 8.0epss 0.00

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an unauthenticated user to execute arbitrary JavaScript in a user's browser session due to…

  • CVE-2026-10086HigJun 25, 2026
    risk 0.00cvss 8.7epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 16.4 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with developer-role permissions to execute arbitrary client-side code in…

  • CVE-2026-0934LowJun 25, 2026
    risk 0.00cvss 3.8epss 0.00

    GitLab has remediated an issue in GitLab EE affecting all versions from 17.9 before 18.11.6, 19.0 before 19.0.3, and 19.1 before 19.1.1 that under certain conditions could have allowed an authenticated user with custom role permissions to view, create, or delete protected…

  • CVE-2023-5106HigOct 2, 2023
    risk 0.00cvss 8.2epss 0.01

    An issue has been discovered in Ultimate-licensed GitLab EE affecting all versions starting 13.12 prior to 16.2.8, 16.3.0 prior to 16.3.5, and 16.4.0 prior to 16.4.1 that could allow an attacker to impersonate users in CI pipelines through direct transfer group imports.

  • CVE-2023-31485MedApr 29, 2023
    risk 0.00cvss 5.9epss 0.01

    GitLab::API::v4 through 0.26 does not verify TLS certificates when connecting to a GitLab server, enabling machine-in-the-middle attacks.

  • CVE-2015-6665Aug 24, 2015
    risk 0.00cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in the Ajax handler in Drupal 7.x before 7.39 and the Ctools module 6.x-1.x before 6.x-1.14 for Drupal allows remote attackers to inject arbitrary web script or HTML via vectors involving a whitelisted HTML element, possibly related to…

  • CVE-2013-4489May 17, 2014
    risk 0.00cvss epss 0.01

    The Grit gem for Ruby, as used in GitLab 5.2 before 5.4.1 and 6.x before 6.2.3, allows remote authenticated users to execute arbitrary commands, as demonstrated by the search box for the GitLab code search feature.

  • CVE-2014-3456May 13, 2014
    risk 0.00cvss epss 0.01

    Cross-site scripting (XSS) vulnerability in GitLab Enterprise Edition (EE) 6.6.0 before 6.6.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2013-4546May 13, 2014
    risk 0.00cvss epss 0.02

    The repository import feature in gitlab-shell before 1.7.4, as used in GitLab, allows remote authenticated users to execute arbitrary commands via the import URL.

  • CVE-2013-4581May 12, 2014
    risk 0.00cvss epss 0.02

    GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.

  • CVE-2013-4580May 12, 2014
    risk 0.00cvss epss 0.01

    GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.

Page 29 of 29