Skip to main content

Vendor archive

gitlab CVEs

Beta · best-effort

1,421 CVEs tagged to vendor gitlab57 Critical, 294 High, 889 Medium, 180 Low, 1 Unrated.

CVE-2025-4972

Published Jul 10, 2025

An issue has been discovered in GitLab EE affecting all versions from 18.0 before 18.0.4 and 18.1 before 18.1.2 that could have allowed authenticated users with invitation privile…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-3396

Published Jul 10, 2025

An issue has been discovered in GitLab EE affecting all versions from 13.3 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that could have allowed authenticated project…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5846

Published Jun 26, 2025

An issue has been discovered in GitLab EE affecting all versions from 16.10 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-5315

Published Jun 26, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated user…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-3279

Published Jun 26, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated atta…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-2938

Published Jun 26, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated user…

CVSS 3.1 · Low
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-1754

Published Jun 26, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated at…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-5600

Published Jun 20, 2025

An issue has been discovered in GitLab EE affecting all versions starting from 16.0 before 16.3.6, all versions starting from 16.4 before 16.4.2, all versions starting from 16.5 b…

CVSS 3.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-4994

Published Jun 20, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 16.1.0 before 16.11.5, all versions starting from 17.0 before 17.0.3, all versions starting from 17.1.0 be…

CVSS 8.1 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-4025

Published Jun 20, 2025

A Denial of Service (DoS) condition has been discovered in GitLab CE/EE affecting all versions from 7.10 prior before 16.11.5, version 17.0 before 17.0.3, and 17.1 before 17.1.1.…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5121

Published Jun 20, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.4 and 18.0 before 18.0.2. A missing authorization check may have allowed compliance fra…

CVSS 8.5 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-2443

Published Jun 20, 2025

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting a…

CVSS 8.7 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-7586

Published Jun 20, 2025

An issue was discovered in GitLab EE affecting all versions starting from 17.0 prior to 17.0.6, starting from 17.1 prior to 17.1.4, and starting from 17.2 prior to 17.2.2, where w…

CVSS 4.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5982

Published Jun 12, 2025

An issue has been discovered in GitLab EE affecting all versions from 12.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Under certain conditions users could bypas…

CVSS 3.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-9512

Published Jun 12, 2025

An issue has been discovered in GitLab EE affecting all versions prior to 17.10.8, 17.11 prior to 17.11.4, and 18.0 prior to 18.0.2. It may have been possible for private reposito…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-5195

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. It was possible for authenticated users…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-0673

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2, allow an attacker to trigger an infinit…

CVSS 7.5 · High
evidence mentions
3
Buzz score
29.9
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-5996

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 2.1.0 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. A lack of input validation in HTTP res…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-4278

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions starting with 18.0 before 18.0.2. Under certain conditions html injection in new search page could lead to acco…

CVSS 8.7 · High
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-2254

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper output encoding in the snipper…

CVSS 8.7 · High
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-1516

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 8.7 before 17.10.8, 17.11 before 17.11.4, and 18.0 before 18.0.2. Improper input validation in Tokens Name…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-1478

Published Jun 12, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 8.13 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A lack of input validation in Board Nam…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
25.4
Vendor/product tagsBeta · best-effort

CVE-2025-1763

Published May 30, 2025

An issue has been discovered in GitLab EE that allows for cross-site-scripting attack and content security policy bypass in a user's browser under specific conditions, affecting a…

CVSS 8.7 · High
evidence mentions
2
Buzz score
22.0
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2024-9163

Published May 23, 2025

A business logic error in GitLab CE/EE affecting all versions starting from 12.1 prior to 17.10.7, 17.11 prior to 17.11.3 and 18.0 prior to 18.0.1 where an attacker can cause a br…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2024-7803

Published May 23, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 17.10.7, 17.11 before 17.11.3, and 18.0 before 18.0.1. A Discord webhook integration may cause…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 226-250 of 1,421 CVEsPage 10 of 57