2024

2023

2022

2021

2020

CVE-2020-10075 (v3: 6.1) 13 Mar 2020
GitLab 12.5 through 12.8.1 allows HTML Injection. A particular error header was potentially susceptible to injection or potentially other vulnerabilities via unescaped input.

2019

CVE-2019-20142 (v3: 4.3) 13 Jan 2020
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) 12.3 through 12.6.1. It allows Denial of Service.
CVE-2019-15575 (v3: 7.5) 18 Dec 2019
A command injection exists in GitLab CE/EE
CVE-2019-15724 (v3: 6.1) 16 Sep 2019
An issue was discovered in GitLab Community and Enterprise Edition 11.10 through 12.2.1. Label descriptions are vulnerable to HTML injection.
CVE-2019-6781 (v3: 7.5) 17 May 2019
An Improper Input Validation issue was discovered in GitLab Community and Enterprise Edition before 11.5.8, 11.6.x before 11.6.6, and 11.7.x before 11.7.1. It was possible to use the profile name to inject a potentially malicious link into notification emails.

2018

2017

2016

2015