← Back

Gitlab

gitlab

Vendor: Gitlab • 1,408 CVEs

CVEs (1,408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Client-Side code injection through Mermaid markup in GitLab CE/EE 12.9 and later through 13.0.1 allows a specially crafted Mermaid payload to PUT requests on behalf of other users via clicking on a link
1Gitlab
1Gitlab
Jun 17, 2026
Jun 19, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An authorization issue in the mirroring logic allowed read access to private repositories in GitLab CE/EE 10.6 and later through 13.0.5
6Apple
GitlabNetapp+3 more
15Active Iq Unified Manager
Cloud BackupClustered Data Ontap+12 more
Jun 17, 2026
Jun 15, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
libpcre in PCRE before 8.44 allows an integer overflow via a large number after a (?C substring.
1Gitlab
1Gitlab
Jun 17, 2026
Jun 10, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Stored Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code in the blobs API in all previous GitLab CE/EE versions through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 10, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Missing permission check on fork relation creation in GitLab CE/EE 11.3 and later through 13.0.1 allows guest users to create a fork relation on restricted public projects via API
1Gitlab
1Gitlab
Jun 17, 2026
Jun 10, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Reflected Cross-Site Scripting vulnerability allowed the execution of arbitrary Javascript code on the Static Site Editor in GitLab CE/EE 12.10 and later through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 10, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
A specially crafted request could be used to confirm the existence of files hosted on object storage services, without disclosing their contents. This vulnerability affects GitLab CE/EE 12.10 and later through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 10, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A Stored Cross-Site Scripting vulnerability allowed the execution on Javascript payloads on the Metrics Dashboard in GitLab CE/EE 12.8 and later through 13.0.1
1Gitlab
1Gitlab
Jun 17, 2026
Jun 9, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
Insecure authorization in Project Deploy Keys in GitLab CE/EE 12.8 and later through 13.0.1 allows users to update permissions of other users' deploy keys under certain conditions
1Gitlab
1Gitlab
Jun 17, 2026
May 7, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab EE 12.8 and later allows Exposure of Sensitive Information to an Unauthorized Actor via NuGet.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 29, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab 10.8 through 12.9 has a vulnerability that allows someone to mirror a repository even if the feature is not activated.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 29, 2020
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
GitLab 9.5.9 through 12.9 is vulnerable to stored XSS in an admin notification feature.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 29, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab 12.6 through 12.9 is vulnerable to a privilege escalation that allows an external user to create a personal snippet through the API.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 22, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue was discovered in GitLab CE and EE 8.15 through 12.9.2. Members of a group could still have access after the group is deleted.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab 10.7.0 and later through 12.9.2. A Workhorse bypass could lead to job artifact uploads and file disclosure (Exposure of Sensitive Information) via request smuggling.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 22, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Expo...Show more
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 12.7.9, 12.8.x before 12.8.9, and 12.9.x before 12.9.3. A Workhorse bypass could lead to NuGet package and file disclosure (Exposure of Sensitive Information) via request smuggling.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab EE/CE 9.0 to 12.9 allows a maintainer to modify other maintainers' pipeline trigger descriptions within the same project.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GitLab EE/CE 8.0.rc1 to 12.9 is vulnerable to a blind SSRF in the FogBugz integration.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab EE/CE 11.10 to 12.9 is leaking information on restricted CI pipelines metrics to unauthorized users.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab EE/CE 8.11 to 12.9 is leaking information on Issues opened in a public project and then moved to a private project through Web-UI and GraphQL API.