Gitlab Ce vulnerabilities

572 known vulnerabilities affecting gitlab/gitlab_ce.

Total CVEs
572
CISA KEV
3
actively exploited
Public exploits
14
Exploited in wild
2
Severity breakdown
CRITICAL18HIGH128MEDIUM342LOW84

Vulnerabilities

Page 6 of 29
CVE-2025-4225MEDIUMCVSS 5.32025-08-27
CVE-2025-4225 [MEDIUM] CWE-770 CVE-2025-4225: An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that unde CVE-2025-4225: An issue has been discovered in GitLab CE/EE affecting all versions from 14.1 before 18.1.5, 18.2 before 18.2.5, and 18.3 before 18.3.1 that that under certain conditions could have allowed an unauthenticated attacker to cause a denial-of-service condition affecting all users by sending
gitlab
CVE-2025-6186HIGHCVSS 8.72025-08-13
CVE-2025-6186 [HIGH] CWE-79 CVE-2025-6186: An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authentica CVE-2025-6186: An issue has been discovered in GitLab CE/EE affecting all versions from 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to achieve account takeover by injecting malicious HTML into work item names.
gitlab
CVE-2025-7734HIGHCVSS 8.72025-08-13
CVE-2025-7734 [HIGH] CWE-79 CVE-2025-7734: An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under cer CVE-2025-7734: An issue has been discovered in GitLab CE/EE affecting all versions from 14.2 before 18.0.6, 18.1 before 18.1.4 and 18.2 before 18.2.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.
gitlab
CVE-2025-7739HIGHCVSS 8.72025-08-13
CVE-2025-7739 [HIGH] CWE-79 CVE-2025-7739: An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authent CVE-2025-7739: An issue has been discovered in GitLab CE/EE affecting all versions from 18.2 before 18.2.2 that, under certain conditions, could have allowed authenticated users to achieve stored cross-site scripting by injecting malicious HTML content in scoped label descriptions.
gitlab
CVE-2025-2937MEDIUMCVSS 6.52025-08-13
CVE-2025-2937 [MEDIUM] CWE-1333 CVE-2025-2937: An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could hav CVE-2025-2937: An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users to create a denial of service condition by sending specially crafted markdown payloads to the Wiki feature.
gitlab
CVE-2025-5819MEDIUMCVSS 5.02025-08-13
CVE-2025-5819 [MEDIUM] CWE-732 CVE-2025-5819: An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could hav CVE-2025-5819: An issue has been discovered in GitLab CE/EE affecting all versions from 15.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users with developer access to obtain ID tokens for protected branches under certain circumstances.
gitlab
CVE-2025-2614MEDIUMCVSS 6.52025-08-13
CVE-2025-2614 [MEDIUM] CWE-770 CVE-2025-2614: An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could hav CVE-2025-2614: An issue has been discovered in GitLab CE/EE affecting all versions from 11.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an authenticated user to cause a denial of service condition by creating specially crafted content that consumes excessive serve
gitlab
CVE-2024-10219MEDIUMCVSS 6.52025-08-13
CVE-2024-10219 [MEDIUM] CWE-863 CVE-2024-10219: An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under cer CVE-2024-10219: An issue has been discovered in GitLab CE/EE affecting all versions from 15.6 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users to bypass access controls and download private artifacts by accessing specific A
gitlab
CVE-2024-12303MEDIUMCVSS 6.72025-08-13
CVE-2024-12303 [MEDIUM] CWE-266 CVE-2024-12303: An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under cer CVE-2024-12303: An issue has been discovered in GitLab CE/EE affecting all versions from 17.7 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that under certain conditions could have allowed authenticated users with specific roles and permissions to delete issues including confidential ones
gitlab
CVE-2025-1477MEDIUMCVSS 6.52025-08-13
CVE-2025-1477 [MEDIUM] CWE-770 CVE-2025-1477: An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could hav CVE-2025-1477: An issue has been discovered in GitLab CE/EE affecting all versions from 8.14 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed an unauthenticated user to create a denial of service condition by sending specially crafted payloads to specific integration AP
gitlab
CVE-2025-7001MEDIUMCVSS 4.32025-07-24
CVE-2025-7001 [MEDIUM] CWE-1220 CVE-2025-7001: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could hav CVE-2025-7001: An issue has been discovered in GitLab CE/EE affecting all versions from 15.0 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed priviledged users to access certain resource_group information through the API which should have been unavailable.
gitlab
CVE-2025-0765MEDIUMCVSS 4.32025-07-24
CVE-2025-0765 [MEDIUM] CWE-863 CVE-2025-0765: An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could hav CVE-2025-0765: An issue has been discovered in GitLab CE/EE affecting all versions from 17.9 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an unauthorized user to access custom service desk email addresses.
gitlab
CVE-2025-1299MEDIUMCVSS 4.32025-07-24
CVE-2025-1299 [MEDIUM] CWE-862 CVE-2025-1299: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, a CVE-2025-1299: An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 18.0.5, all versions starting from 18.1 before 18.1.3, all versions starting from 18.2 before 18.2.1 that, under circumstances, could have allowed an unauthorized user to read deployment job log
gitlab
CVE-2025-4439HIGHCVSS 7.72025-07-23
CVE-2025-4439 [HIGH] CWE-79 CVE-2025-4439: An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could ha CVE-2025-4439: An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that could have allowed an authenticated user to perform cross-site scripting attacks when the instance is served through certain content delivery network
gitlab
CVE-2025-4700HIGHCVSS 8.72025-07-23
CVE-2025-4700 [HIGH] CWE-79 CVE-2025-4700: An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under s CVE-2025-4700: An issue has been discovered in GitLab CE/EE affecting all versions from 15.10 before 18.0.5, 18.1 before 18.1.3, and 18.2 before 18.2.1 that, under specific circumstances, could have potentially allowed a successful attacker to trigger unintended content rendering leading to XSS.
gitlab
CVE-2025-6948HIGHCVSS 8.72025-07-10
CVE-2025-6948 [HIGH] CWE-79 CVE-2025-6948: An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under CVE-2025-6948: An issue has been discovered in GitLab CE/EE affecting all versions from 17.11 before 17.11.6, 18.0 before 18.0.4, and 18.1 before 18.1.2 that, under certain conditions, could have allowed a successful attacker to execute actions on behalf of users by injecting malicious content.
gitlab
CVE-2025-1754MEDIUMCVSS 5.32025-06-26
CVE-2025-1754 [MEDIUM] CWE-306 CVE-2025-1754: An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could ha CVE-2025-1754: An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed unauthenticated attackers to upload arbitrary files to public projects by sending crafted API requests, potentially leading to
gitlab
CVE-2025-3279MEDIUMCVSS 6.52025-06-26
CVE-2025-3279 [MEDIUM] CWE-770 CVE-2025-3279: An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could ha CVE-2025-3279: An issue has been discovered in GitLab CE/EE affecting all versions from 10.7 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated attackers to create a DoS condition by sending crafted GraphQL requests.
gitlab
CVE-2025-5315MEDIUMCVSS 4.32025-06-26
CVE-2025-5315 [MEDIUM] CWE-862 CVE-2025-5315: An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could ha CVE-2025-5315: An issue has been discovered in GitLab CE/EE affecting all versions from 17.2 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users with Guest role permissions to add child items to incident work items by sending crafted API requests that
gitlab
CVE-2025-2938LOWCVSS 3.12025-06-26
CVE-2025-2938 [LOW] CWE-840 CVE-2025-2938: An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could ha CVE-2025-2938: An issue has been discovered in GitLab CE/EE affecting all versions from 17.3 before 17.11.5, 18.0 before 18.0.3, and 18.1 before 18.1.1 that could have allowed authenticated users to gain elevated project privileges by requesting access to projects where role modifications during the appro
gitlab