gitlab
1,383 tracked vulnerabilities.
CVE-2025-9958
HIGH
GitLab CE/EE <18.2.7-18.4.1 - Info Disclosure
Sep 26, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-9642
HIGH
GitLab 14.10-18.2.6, 18.3-18.3.2, 18.4 - Cross-Site Scripting
Sep 26, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-7691
MEDIUM
GitLab EE <18.2.7-<18.3.3-<18.4.1 - Privilege Escalation
Sep 26, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10871
LOW
GitLab EE 16.6-18.2.6, 18.3-18.3.2, 18.4 - Authenticated Privilege Escalation via Custom Role Assignment
Sep 26, 2025
CVSS 3.8
EPSS 0.00
CVE-2025-10867
LOW
GitLab 18.1-18.2.6, 18.3-18.3.2, 18.4-18.4.0 - Authenticated Denial of Service via GraphQL API
Sep 26, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-10858
HIGH
GitLab < 18.2.7, 18.3 < 18.3.3, 18.4 < 18.4.1 - Unauthenticated Denial of Service via Large JSON File Upload
Sep 26, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-7337
MEDIUM
GitLab 7.8-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Authenticated Denial of Service via Large File Upload
Sep 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-6769
MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Info Disclosure
Sep 12, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-6454
HIGH
GitLab 16.11-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Authenticated Server-Side Request Forgery via Proxy Request Injection
Sep 12, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-2256
HIGH
GitLab 7.12-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Denial of Service via Large SAML Responses
Sep 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-1250
MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Privilege Escalation
Sep 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10094
MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Privilege Escalation
Sep 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-5101
MEDIUM
GitLab < 18.1.5, 18.2 < 18.2.5, 18.3 < 18.3.1 - Authenticated Code Injection via Branch/Tag Ambiguity
Aug 27, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-4225
MEDIUM
GitLab 14.1-18.1.4, 18.2-18.2.4, 18.3-18.3.0 - Unauthenticated Denial of Service via GraphQL Requests
Aug 27, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3601
MEDIUM
GitLab 8.15-18.1.4, 18.2-18.2.4, 18.3-18.3.0 - Authenticated Denial of Service via Large URL Response
Aug 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-2246
MEDIUM
GitLab < 18.1.5, 18.2 < 18.2.5, 18.3 < 18.3.1 - Unauthenticated Sensitive CI/CD Variable Exposure via GraphQL API
Aug 27, 2025
CVSS 5.8
EPSS 0.00
CVE-2025-8770
MEDIUM
GitLab 18.0-18.0.6, 18.1-18.1.4, 18.2-18.2.2 - Merge Request Approval Policy Bypass
Aug 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-7739
HIGH
GitLab 18.2.0-18.2.1 - Authenticated Stored Cross-Site Scripting in Scoped Label Descriptions
Aug 13, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-7734
HIGH
GitLab CE/EE <18.0.6-18.2.2 - Code Injection
Aug 13, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-6186
HIGH
GitLab 18.1-18.1.4 and 18.2-18.2.2 - Authenticated Account Takeover via Work Item Name HTML Injection
Aug 13, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-5819
MEDIUM
GitLab CE/EE <18.0.6-18.2.2 - Info Disclosure
Aug 13, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-2937
MEDIUM
GitLab 13.2-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Authenticated Denial of Service via Wiki Markdown Payload
Aug 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-2614
MEDIUM
GitLab 11.6-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Authenticated Denial of Service via Resource Exhaustion
Aug 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-2498
LOW
Gitlab EE <18.0.6-18.2.2 - Auth Bypass
Aug 13, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-1477
MEDIUM
GitLab 8.14-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Unauthenticated Denial of Service via Integration API Endpoints
Aug 13, 2025
CVSS 6.5
EPSS 0.00