VYPR
Vendor

Gitlist

Products
1
CVEs
6
Across products
6
Status
Private

Products

1

Recent CVEs

6
  • CVE-2026-82668HigAug 31, 2026
    risk 0.41cvss 7.3epss 0.02

    A security vulnerability has been detected in klaussilveira GitList 2.0.0. Affected by this vulnerability is the function getDefaultBranch of the file src/SCM/System/Git/CommandLine.php of the component Git Command Line. Such manipulation leads to os command injection. The…

  • CVE-2026-82669MedAug 31, 2026
    risk 0.27cvss 5.3epss 0.00

    A vulnerability was detected in klaussilveira GitList 2.0.0. Affected by this issue is the function SimpleXMLElement of the file src/SCM/System/Git/CommandLine.php of the component XML Parsing. Performing a manipulation results in denial of service. The attack is possible to be…

  • CVE-2014-4511Jul 22, 2014
    risk 0.10cvss —epss 0.83

    Gitlist before 0.5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the file name in the URI of a request for a (1) blame, (2) file, or (3) stats page, as demonstrated by requests to blame/master/, master/, and stats/master/.

  • CVE-2018-1000533CriJun 26, 2018
    risk 0.09cvss 9.8epss 0.73

    klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This…

  • CVE-2013-7392Jul 22, 2014
    risk 0.04cvss —epss 0.08

    Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.

  • CVE-2014-5023Jul 22, 2014
    risk 0.03cvss —epss 0.03

    Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkout -b" command.