gitlab
1,383 tracked vulnerabilities.
CVE-2025-12073
MEDIUM
GitLab 18.0-18.6.5, 18.7-18.7.3, 18.8-18.8.3 - Authenticated Server-Side Request Forgery via Git Repository Import
Feb 11, 2026
CVSS 4.3
EPSS 0.00
CVE-2025-13928
HIGH
GitLab 17.7-18.6.3, 18.7-18.7.1, 18.8-18.8.1 - Unauthenticated Denial of Service via API Endpoint Authorization Bypass
Jan 22, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-13927
HIGH
GitLab 11.9-18.6.3, 18.7-18.7.1, 18.8-18.8.1 - Unauthenticated Denial of Service via Malformed Authentication Data
Jan 22, 2026
CVSS 7.5
EPSS 0.00
CVE-2025-13335
MEDIUM
GitLab 17.1-18.6.3, 18.7-18.7.1, 18.8-18.8.1 - Authenticated Denial of Service via Wiki Cycle Detection Bypass
Jan 22, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-11224
HIGH
GitLab 15.10-18.3.5, 18.4-18.4.3, 18.5-18.5.1 - Authenticated Stored Cross-Site Scripting via Kubernetes Proxy
Jan 14, 2026
CVSS 7.7
EPSS 0.00
CVE-2025-9222
HIGH
GitLab 18.2.2-18.5.4, 18.6-18.6.2, 18.7-18.7.0 - Authenticated Stored Cross-Site Scripting via GitLab Flavored Markdown
Jan 09, 2026
CVSS 8.7
EPSS 0.00
CVE-2025-3950
LOW
GitLab CE/EE <18.5.5-18.7.1 - Info Disclosure
Jan 09, 2026
CVSS 3.5
EPSS 0.00
CVE-2025-13781
MEDIUM
GitLab 18.5-18.5.4, 18.6-18.6.2, 18.7-18.7.0 - Authenticated Missing Authorization in GraphQL Mutations
Jan 09, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-13772
HIGH
GitLab 18.4.0-18.5.4, 18.6.0-18.6.2, 18.7.0 - Authenticated Missing Authorization via Namespace Identifier Manipulation
Jan 09, 2026
CVSS 7.1
EPSS 0.00
CVE-2025-13761
HIGH
GitLab 18.6-18.6.2 and 18.7-18.7.0 - Unauthenticated Stored Cross-Site Scripting
Jan 09, 2026
CVSS 8.0
EPSS 0.00
CVE-2025-11246
MEDIUM
GitLab CE/EE <18.5.5-18.7.1 - Privilege Escalation
Jan 09, 2026
CVSS 5.4
EPSS 0.00
CVE-2025-10569
MEDIUM
GitLab 8.3-18.5.5, 18.6-18.6.3, 18.7-18.7.1 - Authenticated Denial of Service via External API Response
Jan 09, 2026
CVSS 6.5
EPSS 0.00
CVE-2025-12734
LOW
GitLab 15.6-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Cross-Site Scripting via Merge Request Title
Dec 11, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-12029
HIGH
GitLab 15.11-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Unauthenticated Cross-Site Scripting in Swagger UI
Dec 11, 2025
CVSS 8.0
EPSS 0.00
CVE-2025-8405
HIGH
GitLab CE/EE <18.4.6-18.6.2 - Privilege Escalation
Dec 11, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-4097
MEDIUM
GitLab 11.10-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Denial of Service via Image Upload
Dec 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-11984
MEDIUM
GitLab CE/EE <18.4.6-18.6.2 - Auth Bypass
Dec 11, 2025
CVSS 6.8
EPSS 0.00
CVE-2025-11247
MEDIUM
GitLab EE <18.4.6-18.6.2 - Info Disclosure
Dec 11, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-14157
MEDIUM
GitLab 6.3-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Denial of Service via Large API Content Parameters
Dec 11, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-13978
MEDIUM
GitLab 17.5-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Private Project Name Disclosure via API Requests
Dec 11, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-12716
HIGH
GitLab CE/EE <18.4.6-18.6.2 - Privilege Escalation
Dec 11, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-12562
HIGH
GitLab 11.10-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Unauthenticated Denial of Service via GraphQL Query Complexity Bypass
Dec 11, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-7449
MEDIUM
GitLab 8.3-18.4.5, 18.5-18.5.3, 18.6-18.6.1 - Authenticated Denial of Service via HTTP Response Processing
Nov 26, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-6195
MEDIUM
GitLab EE <18.4.5-18.6.1 - Info Disclosure
Nov 26, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-13611
LOW
GitLab 13.2-18.5.4 and 18.6-18.6.2 - Authenticated Sensitive Token Exposure via Log File Insertion
Nov 26, 2025
CVSS 2.0
EPSS 0.00