Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

Filtering: Tag: gitlab Clear
ID Title
CVE-2025-12664 Vulnerability in dos (CVE-2025-12664)
vulnerability in dos (CVE-2025-12664). Risk of unauthorized operations or information disclosure.
CVE-2026-2370 Vulnerability in gitlab (CVE-2026-2370)
vulnerability in gitlab (CVE-2026-2370). Confidential information can be exposed externally. Mitigation: upgrade to `18.8.7, 18.9.3, 18.10.1` or later.
CVE-2021-22175 KEV [KEV] SSRF (Server-Side Request Forgery) in gitlab (CVE-2021-22175)
SSRF in gitlab (CVE-2021-22175). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-39935 KEV [KEV] SSRF (Server-Side Request Forgery) in Gitlab community-and-enterprise-editions (CVE-2021-39935)
SSRF in Gitlab community-and-enterprise-editions (CVE-2021-39935). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2025-9222 Cross-Site Scripting (XSS) in gitlab (CVE-2025-9222)
cross-site scripting in gitlab (CVE-2025-9222). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
CVE-2025-13761 Cross-Site Scripting (XSS) in gitlab (CVE-2025-13761)
cross-site scripting in gitlab (CVE-2025-13761). Confidential information can be exposed externally. Mitigation: upgrade to `18.6.3, 18.7.1` or later.
CVE-2025-13772 Vulnerability in gitlab (CVE-2025-13772)
vulnerability in gitlab (CVE-2025-13772). Confidential information can be exposed externally. Mitigation: upgrade to `18.5.5, 18.6.3, 18.7.1` or later.
CVE-2023-7028 KEV [KEV] Vulnerability in gitlab (CVE-2023-7028)
vulnerability in gitlab (CVE-2023-7028). Risk of unauthorized operations or information disclosure. Listed in CISA KEV — actively exploited.
CVE-2021-39911 Vulnerability in gitlab (CVE-2021-39911)
vulnerability in gitlab (CVE-2021-39911). Risk of unauthorized operations or information disclosure.
CVE-2021-39913 Privilege Escalation in gitlab (CVE-2021-39913)
vulnerability in gitlab (CVE-2021-39913). Confidential information can be exposed externally.
CVE-2021-39904 Authorization Flaw in gitlab (CVE-2021-39904)
vulnerability in gitlab (CVE-2021-39904). Risk of unauthorized operations or information disclosure.
CVE-2021-22205 KEV [KEV] Code Injection in Gitlab community-and-enterprise-editions (CVE-2021-22205)
code injection in Gitlab community-and-enterprise-editions (CVE-2021-22205). Successful exploitation can lead to full system takeover. Listed in CISA KEV — actively exploited.
CVE-2017-17716 Vulnerability in gitlab (CVE-2017-17716)
vulnerability in gitlab (CVE-2017-17716). Confidential information can be exposed externally.
CVE-2017-12426 Vulnerability in gitlab (CVE-2017-12426)
vulnerability in gitlab (CVE-2017-12426). Successful exploitation can lead to full system takeover.
CVE-2017-11437 Vulnerability in gitlab (CVE-2017-11437)
vulnerability in gitlab (CVE-2017-11437). Confidential information can be exposed externally.
CVE-2017-11438 Privilege Escalation in gitlab (CVE-2017-11438)
vulnerability in gitlab (CVE-2017-11438). Risk of unauthorized operations or information disclosure.
CVE-2017-8778 Cross-Site Scripting (XSS) in gitlab (CVE-2017-8778)
cross-site scripting in gitlab (CVE-2017-8778). Risk of unauthorized operations or information disclosure.
CVE-2016-9469 Vulnerability in gitlab (CVE-2016-9469)
vulnerability in gitlab (CVE-2016-9469). Data can be tampered with by attackers.
CVE-2017-0882 Vulnerability in gitlab (CVE-2017-0882)
vulnerability in gitlab (CVE-2017-0882). Risk of unauthorized operations or information disclosure.
CVE-2016-4340 Vulnerability in gitlab (CVE-2016-4340)
vulnerability in gitlab (CVE-2016-4340). Successful exploitation can lead to full system takeover.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →