gitlab records
1,481 published records for vendor gitlab.
Researcher profile
- Entered KEV
- 5 · 0.3%
- Weaponized
- 11 · 0.7%
- Pre-auth RCE
- 26
- With a fix record
- 42%
- Median publish → KEV
- 194 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')180
- CWE-863 Incorrect Authorization129
- CWE-770 Allocation of Resources Without Limits or Throttling93
- CWE-862 Missing Authorization81
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor63
- CWE-400 Uncontrolled Resource Consumption48
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
1,481 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2021-22205Weaponized | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Critical10.0 | KEV | 99.7% | Apr 23, 2021 |
97Now | CVE-2023-7028Weaponized | Weak Password Recovery Mechanism for Forgotten Password in GitLabgitlab · gitlab · CWE-640 | Critical9.8 | KEV | 94.6% | Jan 12, 2024 |
97Now | CVE-2026-85706Weaponized | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLabgitlab · gitlab · CWE-22 | Critical10.0 | KEV | 91.4% | Sep 11, 2026 |
85Now | CVE-2021-22175Weaponized | When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versionsgitlab · gitlab · CWE-918 | Critical9.8 | KEV | 53.4% | Jun 11, 2021 |
71This week | CVE-2021-39935Weaponized | An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 beforegitlab · gitlab · CWE-918 | High7.5 | KEV | 35.6% | Dec 13, 2021 |
65This week | CVE-2022-2992Weaponized | A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated usgitlab · gitlab · CWE-74 | Critical9.9 | — | 86.2% | Oct 17, 2022 |
62This week | CVE-2022-2884Proof of concept | A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an authgitlab · gitlab · CWE-78 | Critical9.9 | — | 75.7% | Oct 17, 2022 |
62This week | CVE-2022-1162Proof of concept | A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.gitlab · gitlab · CWE-798 | Critical9.8 | — | 75.6% | Apr 4, 2022 |
58Plan | CVE-2022-2185Proof of concept | A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prgitlab · gitlab · CWE-78 | High8.8 | — | 76.7% | Jul 1, 2022 |
55Plan | CVE-2020-13340No exploit | An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Loggitlab · gitlab · CWE-79 | High8.7 | — | 68.6% | Oct 8, 2020 |
54Plan | CVE-2026-19478Proof of concept | Improper Control of Generation of Code ('Code Injection') in GitLabgitlab · gitlab · CWE-94 | Critical9.1 | — | 60.2% | Aug 17, 2026 |
54Plan | CVE-2018-14364No exploit | GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write acgitlab · gitlab · CWE-22 | Critical9.8 | — | 50.1% | Jul 18, 2018 |
51Plan | CVE-2023-2825Weaponized | An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.gitlab · gitlab · CWE-22 | High7.5 | — | 71.6% | May 26, 2023 |
50Plan | CVE-2023-2442No exploit | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befogitlab · gitlab · CWE-79 | Medium5.4 | — | 96.1% | Jun 7, 2023 |
49Plan | CVE-2023-0050No exploit | An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.gitlab · gitlab · CWE-79 | Medium5.4 | — | 92.4% | Mar 9, 2023 |
49Plan | CVE-2022-1175Proof of concept | Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versiogitlab · gitlab · CWE-79 | Medium6.1 | — | 82.0% | Apr 4, 2022 |
49Plan | CVE-2024-1451No exploit | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLabgitlab · gitlab · CWE-79 | High8.7 | — | 51.5% | Feb 21, 2024 |
47Plan | CVE-2022-1190No exploit | Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an attagitlab · gitlab · CWE-79 | Medium5.4 | — | 87.4% | Apr 4, 2022 |
47Plan | CVE-2022-3265No exploit | A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 priogitlab · gitlab · CWE-79 | Medium5.4 | — | 86.3% | Nov 9, 2022 |
45Plan | CVE-2021-4191Weaponized | An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.gitlab · gitlab | Medium5.3 | — | 80.0% | Mar 28, 2022 |
43Plan | CVE-2021-22238No exploit | An issue has been discovered in GitLab affecting all versions starting with 13.3.gitlab · gitlab · CWE-79 | Medium5.4 | — | 71.8% | Aug 20, 2021 |
43Plan | CVE-2023-3364No exploit | Inefficient Regular Expression Complexity in GitLabgitlab · gitlab · CWE-1333 | High7.5 | — | 44.5% | Aug 1, 2023 |
43Plan | CVE-2022-0735Proof of concept | An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 beforgitlab · gitlab | Critical9.8 | — | 13.2% | Mar 28, 2022 |
43Plan | CVE-2025-5121No exploit | Missing Authorization in GitLabgitlab · gitlab · CWE-862 | Critical9.9 | — | 12.4% | Jun 20, 2025 |
42Plan | CVE-2023-0921No exploit | Allocation of Resources Without Limits or Throttling in GitLabgitlab · gitlab · CWE-770 | Medium4.3 | — | 84.4% | Jun 6, 2023 |
- CVE-2021-22205100Now
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%gitlab · gitlabApr 23, 2021
- CVE-2023-702897Now
Weak Password Recovery Mechanism for Forgotten Password in GitLab
CriticalCVSS 9.8KEVWeaponizedEPSS 95%gitlab · gitlabJan 12, 2024
- CVE-2026-8570697Now
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
CriticalCVSS 10.0KEVWeaponizedEPSS 91%gitlab · gitlabSep 11, 2026
- CVE-2021-2217585Now
When requests to the internal network for webhooks are enabled, a server-side request forgery vulnerability in GitLab affecting all versions
CriticalCVSS 9.8KEVWeaponizedEPSS 53%gitlab · gitlabJun 11, 2021
- CVE-2021-3993571This week
An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.5 before 14.3.6, all versions starting from 14.4 before
HighCVSS 7.5KEVWeaponizedEPSS 36%gitlab · gitlabDec 13, 2021
- CVE-2022-299265This week
A vulnerability in GitLab CE/EE affecting all versions from 11.10 prior to 15.1.6, 15.2 to 15.2.4, 15.3 to 15.3.2 allows an authenticated us
CriticalCVSS 9.9WeaponizedEPSS 86%gitlab · gitlabOct 17, 2022
- CVE-2022-288462This week
A vulnerability in GitLab CE/EE affecting all versions from 11.3.4 prior to 15.1.5, 15.2 to 15.2.3, 15.3 to 15.3 to 15.3.1 allows an an auth
CriticalCVSS 9.9Proof of conceptEPSS 76%gitlab · gitlabOct 17, 2022
- CVE-2022-116262This week
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g.
CriticalCVSS 9.8Proof of conceptEPSS 76%gitlab · gitlabApr 4, 2022
- CVE-2022-218558Plan
A critical issue has been discovered in GitLab affecting all versions starting from 14.0 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 pr
HighCVSS 8.8Proof of conceptEPSS 77%gitlab · gitlabJul 1, 2022
- CVE-2020-1334055Plan
An issue has been discovered in GitLab affecting all versions prior to 13.2.10, 13.3.7 and 13.4.2: Stored XSS in CI Job Log
HighCVSS 8.7No exploitEPSS 69%gitlab · gitlabOct 8, 2020
- CVE-2026-1947854Plan
Improper Control of Generation of Code ('Code Injection') in GitLab
CriticalCVSS 9.1Proof of conceptEPSS 60%gitlab · gitlabAug 17, 2026
- CVE-2018-1436454Plan
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write ac
CriticalCVSS 9.8No exploitEPSS 50%gitlab · gitlabJul 18, 2018
- CVE-2023-282551Plan
An issue has been discovered in GitLab CE/EE affecting only version 16.0.0.
HighCVSS 7.5WeaponizedEPSS 72%gitlab · gitlabMay 26, 2023
- CVE-2023-244250Plan
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 befo
MediumCVSS 5.4No exploitEPSS 96%gitlab · gitlabJun 7, 2023
- CVE-2023-005049Plan
An issue has been discovered in GitLab affecting all versions starting from 13.7 before 15.7.8, all versions starting from 15.8 before 15.8.
MediumCVSS 5.4No exploitEPSS 92%gitlab · gitlabMar 9, 2023
- CVE-2022-117549Plan
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 before 14.8.5, all versio
MediumCVSS 6.1Proof of conceptEPSS 82%gitlab · gitlabApr 4, 2022
- CVE-2024-145149Plan
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
HighCVSS 8.7No exploitEPSS 51%gitlab · gitlabFeb 21, 2024
- CVE-2022-119047Plan
Improper handling of user input in GitLab CE/EE versions 8.3 prior to 14.7.7, 14.8 prior to 14.8.5, and 14.9 prior to 14.9.2 allowed an atta
MediumCVSS 5.4No exploitEPSS 87%gitlab · gitlabApr 4, 2022
- CVE-2022-326547Plan
A cross-site scripting issue has been discovered in GitLab CE/EE affecting all versions prior to 15.3.5, 15.4 prior to 15.4.4, and 15.5 prio
MediumCVSS 5.4No exploitEPSS 86%gitlab · gitlabNov 9, 2022
- CVE-2021-419145Plan
An issue has been discovered in GitLab CE/EE affecting versions 13.0 to 14.6.5, 14.7 to 14.7.4, and 14.8 to 14.8.2.
MediumCVSS 5.3WeaponizedEPSS 80%gitlab · gitlabMar 28, 2022
- CVE-2021-2223843Plan
An issue has been discovered in GitLab affecting all versions starting with 13.3.
MediumCVSS 5.4No exploitEPSS 72%gitlab · gitlabAug 20, 2021
- CVE-2023-336443Plan
Inefficient Regular Expression Complexity in GitLab
HighCVSS 7.5No exploitEPSS 44%gitlab · gitlabAug 1, 2023
- CVE-2022-073543Plan
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.6.5, all versions starting from 14.7 befor
CriticalCVSS 9.8Proof of conceptEPSS 13%gitlab · gitlabMar 28, 2022
- CVE-2025-512143Plan
Missing Authorization in GitLab
CriticalCVSS 9.9No exploitEPSS 12%gitlab · gitlabJun 20, 2025
- CVE-2023-092142Plan
Allocation of Resources Without Limits or Throttling in GitLab
MediumCVSS 4.3No exploitEPSS 84%gitlab · gitlabJun 6, 2023