gitlab

1,383 tracked vulnerabilities.

CVE-2025-9958 HIGH
GitLab CE/EE <18.2.7-18.4.1 - Info Disclosure
Sep 26, 2025
CVSS 7.7
EPSS 0.00
CVE-2025-9642 HIGH
GitLab 14.10-18.2.6, 18.3-18.3.2, 18.4 - Cross-Site Scripting
Sep 26, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-7691 MEDIUM
GitLab EE <18.2.7-<18.3.3-<18.4.1 - Privilege Escalation
Sep 26, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10871 LOW
GitLab EE 16.6-18.2.6, 18.3-18.3.2, 18.4 - Authenticated Privilege Escalation via Custom Role Assignment
Sep 26, 2025
CVSS 3.8
EPSS 0.00
CVE-2025-10867 LOW
GitLab 18.1-18.2.6, 18.3-18.3.2, 18.4-18.4.0 - Authenticated Denial of Service via GraphQL API
Sep 26, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-10858 HIGH
GitLab < 18.2.7, 18.3 < 18.3.3, 18.4 < 18.4.1 - Unauthenticated Denial of Service via Large JSON File Upload
Sep 26, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-7337 MEDIUM
GitLab 7.8-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Authenticated Denial of Service via Large File Upload
Sep 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-6769 MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Info Disclosure
Sep 12, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-6454 HIGH
GitLab 16.11-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Authenticated Server-Side Request Forgery via Proxy Request Injection
Sep 12, 2025
CVSS 8.5
EPSS 0.00
CVE-2025-2256 HIGH
GitLab 7.12-18.1.5, 18.2-18.2.5, 18.3-18.3.1 - Denial of Service via Large SAML Responses
Sep 12, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-1250 MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Privilege Escalation
Sep 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-10094 MEDIUM
GitLab CE/EE <18.1.6-18.3.2 - Privilege Escalation
Sep 12, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-5101 MEDIUM
GitLab < 18.1.5, 18.2 < 18.2.5, 18.3 < 18.3.1 - Authenticated Code Injection via Branch/Tag Ambiguity
Aug 27, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-4225 MEDIUM
GitLab 14.1-18.1.4, 18.2-18.2.4, 18.3-18.3.0 - Unauthenticated Denial of Service via GraphQL Requests
Aug 27, 2025
CVSS 5.3
EPSS 0.00
CVE-2025-3601 MEDIUM
GitLab 8.15-18.1.4, 18.2-18.2.4, 18.3-18.3.0 - Authenticated Denial of Service via Large URL Response
Aug 27, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-2246 MEDIUM
GitLab < 18.1.5, 18.2 < 18.2.5, 18.3 < 18.3.1 - Unauthenticated Sensitive CI/CD Variable Exposure via GraphQL API
Aug 27, 2025
CVSS 5.8
EPSS 0.00
CVE-2025-8770 MEDIUM
GitLab 18.0-18.0.6, 18.1-18.1.4, 18.2-18.2.2 - Merge Request Approval Policy Bypass
Aug 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-7739 HIGH
GitLab 18.2.0-18.2.1 - Authenticated Stored Cross-Site Scripting in Scoped Label Descriptions
Aug 13, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-7734 HIGH
GitLab CE/EE <18.0.6-18.2.2 - Code Injection
Aug 13, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-6186 HIGH
GitLab 18.1-18.1.4 and 18.2-18.2.2 - Authenticated Account Takeover via Work Item Name HTML Injection
Aug 13, 2025
CVSS 8.7
EPSS 0.00
CVE-2025-5819 MEDIUM
GitLab CE/EE <18.0.6-18.2.2 - Info Disclosure
Aug 13, 2025
CVSS 5.0
EPSS 0.00
CVE-2025-2937 MEDIUM
GitLab 13.2-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Authenticated Denial of Service via Wiki Markdown Payload
Aug 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-2614 MEDIUM
GitLab 11.6-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Authenticated Denial of Service via Resource Exhaustion
Aug 13, 2025
CVSS 6.5
EPSS 0.00
CVE-2025-2498 LOW
Gitlab EE <18.0.6-18.2.2 - Auth Bypass
Aug 13, 2025
CVSS 3.1
EPSS 0.00
CVE-2025-1477 MEDIUM
GitLab 8.14-18.0.5, 18.1-18.1.3, 18.2-18.2.1 - Unauthenticated Denial of Service via Integration API Endpoints
Aug 13, 2025
CVSS 6.5
EPSS 0.00