CVE-2025-9222
- EPSS 0.38%
- Veröffentlicht 09.01.2026 10:15:47
- Zuletzt bearbeitet 15.07.2026 02:17:54
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2.2 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to achieve stored cross-site scripting by exploiting GitLab Flav...
CVE-2025-3950
- EPSS 0.23%
- Veröffentlicht 09.01.2026 10:15:46
- Zuletzt bearbeitet 21.01.2026 19:19:06
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 10.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed a user to leak certain information by referencing specially crafted images that bypass a...
CVE-2025-13761
- EPSS 0.63%
- Veröffentlicht 09.01.2026 10:15:45
- Zuletzt bearbeitet 15.07.2026 02:17:16
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an unauthenticated user to execute arbitrary code in the context of an authenticated user's browser by conv...
CVE-2025-13772
- EPSS 0.39%
- Veröffentlicht 09.01.2026 10:15:45
- Zuletzt bearbeitet 15.07.2026 02:17:16
GitLab has remediated an issue in GitLab EE affecting all versions from 18.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to access and utilize AI model settings from unauthorized namespaces ...
CVE-2025-13781
- EPSS 0.41%
- Veröffentlicht 09.01.2026 10:15:45
- Zuletzt bearbeitet 22.01.2026 21:13:15
GitLab has remediated an issue in GitLab EE affecting all versions from 18.5 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to modify instance-wide AI feature provider settings by exploiting mi...
CVE-2025-10569
- EPSS 0.49%
- Veröffentlicht 09.01.2026 10:15:44
- Zuletzt bearbeitet 22.01.2026 17:30:01
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.3 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user to create a denial of service condition by providing crafted respon...
CVE-2025-11246
- EPSS 0.4%
- Veröffentlicht 09.01.2026 10:15:44
- Zuletzt bearbeitet 22.01.2026 17:28:53
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.4 before 18.5.5, 18.6 before 18.6.3, and 18.7 before 18.7.1 that could have allowed an authenticated user with specific permissions to remove all project runners from unrel...
- EPSS 0.52%
- Veröffentlicht 11.12.2025 07:32:16
- Zuletzt bearbeitet 23.12.2025 21:01:56
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.11 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have, under certain circumstances, allowed an unauthenticated user to perform unauthorized actions o...
CVE-2025-12734
- EPSS 0.26%
- Veröffentlicht 11.12.2025 07:32:01
- Zuletzt bearbeitet 23.12.2025 21:02:22
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other u...
CVE-2025-4097
- EPSS 0.3%
- Veröffentlicht 11.12.2025 04:05:22
- Zuletzt bearbeitet 23.12.2025 21:01:15
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially cra...