← Back

Gitlab

gitlab

Vendor: Gitlab • 1,408 CVEs

CVEs (1,408)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
GitLab EE/CE 8.5 to 12.9 is vulnerable to a an path traversal when moving an issue between projects.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab EE/CE 8.17 to 12.9 is vulnerable to information leakage when querying a merge request widget.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 8, 2020
N/A· v4
4.3 MEDIUM· v3
4.0 MEDIUM· v2
GitLab EE/CE 10.8 to 12.9 is leaking metadata and comments on vulnerabilities to unauthorized users on the vulnerability feedback page.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GitLab 8.10 and later through 12.9 is vulnerable to an SSRF in a project import note feature.
2Debian
Gitlab
2Debian Linux
Gitlab
Jun 17, 2026
Mar 27, 2020
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
GitLab EE/CE 11.1 through 12.9 is vulnerable to parameter tampering on an upload feature that allows an unauthorized user to read content available under specific folders.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab through 12.9 is affected by a potential DoS in repository archive download.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In GitLab EE 11.7 through 12.9, the NPM feature is vulnerable to a path traversal issue.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 27, 2020
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
GitLab EE/CE 8.11 through 12.9.1 allows blocked users to pull/push docker images.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GitLab EE 3.0 through 12.8.1 allows SSRF. An internal investigation revealed that a particular deprecated service was creating a server side request forgery risk.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab 12.1 through 12.8.1 allows XSS. A stored cross-site scripting vulnerability was discovered when displaying merge requests.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
GitLab 10.1 through 12.8.1 has Incorrect Access Control. A scenario was discovered in which a GitLab account could be taken over through an expired link.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab EE 12.4.2 through 12.8.1 allows Denial of Service. It was internally discovered that a potential denial of service involving permissions checks could impact a project home page.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab 12.1 through 12.8.1 allows XSS. A cross-site scripting vulnerability was present in a particular view relating to the Grafana integration.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab 9.3 through 12.8.1 allows XSS. A cross-site scripting vulnerability was found when viewing particular file types.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab 11.7 through 12.8.1 allows Information Disclosure. Under certain group conditions, group epic information was unintentionally being disclosed.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab 8.11 through 12.8.1 allows a Denial of Service when using several features to recursively request eachother,
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
8.1 HIGH· v3
5.5 MEDIUM· v2
GitLab 12.5 through 12.8.1 has Insecure Permissions. Depending on particular group settings, it was possible for invited groups to be given the incorrect permission level.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GitLab before 12.8.2 allows Information Disclosure. Badge images were not being proxied, causing mixed content warnings as well as leaking the IP address of the user.
1Gitlab
1Gitlab
Jun 17, 2026
Mar 13, 2020
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
GitLab 10.4 through 12.8.1 allows Directory Traversal. A particular endpoint was vulnerable to a directory traversal vulnerability, leading to arbitrary file read.