[go7f0](https://hackerone.com/go7f0)
15 credited records · 15 in the last 12 months · 0 in CISA KEV
Names are free text from CNA records; the same person may appear under different spellings. Write to us for corrections.
Credited records
Researchers| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
22Monitor | CVE-2026-3035No exploit | Authentication Bypass Using an Alternate Path or Channel in GitLabgitlab · gitlab · CWE-288 | Medium5.5 | — | 0.3% | Aug 26, 2026 |
18Monitor | CVE-2026-3093No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | Medium4.7 | — | 0.3% | Jul 29, 2026 |
17Monitor | CVE-2026-8472No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.4% | Jul 8, 2026 |
21Monitor | CVE-2026-5309No exploit | Authorization Bypass Through User-Controlled Key in GitLabgitlab · gitlab · CWE-639 | Medium5.4 | — | 0.3% | Jun 25, 2026 |
34Monitor | CVE-2026-8589No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | High8.7 | — | 0.4% | Jun 11, 2026 |
12Monitor | CVE-2026-3553No exploit | Incorrect Authorization in GitLabgitlab · gitlab · CWE-863 | Low3.1 | — | 0.3% | Jun 11, 2026 |
17Monitor | CVE-2026-1338No exploit | Authorization Bypass Through User-Controlled Key in GitLabgitlab · gitlab · CWE-639 | Medium4.3 | — | 0.2% | May 14, 2026 |
17Monitor | CVE-2025-13874No exploit | Authorization Bypass Through User-Controlled Key in GitLabgitlab · gitlab · CWE-639 | Medium4.3 | — | 0.2% | May 14, 2026 |
21Monitor | CVE-2026-4332No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | Medium5.4 | — | 0.3% | Apr 8, 2026 |
21Monitor | CVE-2026-2973No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | Medium5.4 | — | 0.3% | Mar 25, 2026 |
17Monitor | CVE-2026-1663No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.2% | Mar 11, 2026 |
17Monitor | CVE-2026-0602No exploit | Authentication Bypass Using an Alternate Path or Channel in GitLabgitlab · gitlab · CWE-288 | Medium4.3 | — | 0.3% | Mar 11, 2026 |
17Monitor | CVE-2025-14103No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium4.3 | — | 0.2% | Feb 25, 2026 |
17Monitor | CVE-2026-1080No exploit | Authorization Bypass Through User-Controlled Key in GitLabgitlab · gitlab · CWE-639 | Medium4.3 | — | 0.3% | Feb 11, 2026 |
21Monitor | CVE-2025-14592No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Medium5.3 | — | 0.3% | Feb 11, 2026 |
- CVE-2026-303522Monitor
Authentication Bypass Using an Alternate Path or Channel in GitLab
MediumCVSS 5.5No exploitEPSS 0%gitlab · gitlabAug 26, 2026
- CVE-2026-309318Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
MediumCVSS 4.7No exploitEPSS 0%gitlab · gitlabJul 29, 2026
- CVE-2026-847217Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabJul 8, 2026
- CVE-2026-530921Monitor
Authorization Bypass Through User-Controlled Key in GitLab
MediumCVSS 5.4No exploitEPSS 0%gitlab · gitlabJun 25, 2026
- CVE-2026-858934Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
HighCVSS 8.7No exploitEPSS 0%gitlab · gitlabJun 11, 2026
- CVE-2026-355312Monitor
Incorrect Authorization in GitLab
LowCVSS 3.1No exploitEPSS 0%gitlab · gitlabJun 11, 2026
- CVE-2026-133817Monitor
Authorization Bypass Through User-Controlled Key in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabMay 14, 2026
- CVE-2025-1387417Monitor
Authorization Bypass Through User-Controlled Key in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabMay 14, 2026
- CVE-2026-433221Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
MediumCVSS 5.4No exploitEPSS 0%gitlab · gitlabApr 8, 2026
- CVE-2026-297321Monitor
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
MediumCVSS 5.4No exploitEPSS 0%gitlab · gitlabMar 25, 2026
- CVE-2026-166317Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabMar 11, 2026
- CVE-2026-060217Monitor
Authentication Bypass Using an Alternate Path or Channel in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabMar 11, 2026
- CVE-2025-1410317Monitor
Missing Authorization in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabFeb 25, 2026
- CVE-2026-108017Monitor
Authorization Bypass Through User-Controlled Key in GitLab
MediumCVSS 4.3No exploitEPSS 0%gitlab · gitlabFeb 11, 2026
- CVE-2025-1459221Monitor
Missing Authorization in GitLab
MediumCVSS 5.3No exploitEPSS 0%gitlab · gitlabFeb 11, 2026