← Back

Gitlab

gitlab

1,423 CVEs • 11 products

Products (11)

Click to collapse
Toggle
Gitlab
gitlab
Gitlab Shell
gitlab-shell
Runner
runner
Omnibus
omnibus
Gitaly
gitaly
Gitlab Runner
gitlab_runner
\

CVEs (1,423)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gitlab
2Gitlab
Gitlab Shell
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote attackers to execute arbitrary code via a crafted change using SSH.
1Gitlab
1Gitlab
May 6, 2026
May 12, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API c...Show more
GitLab before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1, when using a MySQL backend, allows remote attackers to impersonate arbitrary users and bypass authentication via unspecified API calls.Show less
1Gitlab
1Gitlab
Apr 29, 2026
Jan 24, 2014
N/A· v4
N/A· v3
4.3 MEDIUM· v2
Cross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web script or HTML via a crafted HTML file, as demonstrated by README.html.