Known vulnerabilities in GitLab Enterprise Edition - page 3

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU137129 - Improper Authorization
CVE-2026-13151
CWE-285 Low
No
No
18.11.7, 19.0.4, 19.1.2 08.07.2026 SB2026070844
#VU137130 - Improper Authorization
CVE-2026-6352
CWE-285 Low
No
No
18.11.7, 19.0.4, 19.1.2 08.07.2026 SB2026070844
#VU135172 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-10086
CWE-79 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135173 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-10712
CWE-22 High
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135174 - Exposure of sensitive information to an unauthorized actor
CVE-2026-12053
CWE-200 Low
No
No
19.1.1 25.06.2026 SB2026062554
#VU135175 - Improper Access Control
CVE-2026-5309
CWE-284 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135176 - Incorrect Authorization
CVE-2026-2238
CWE-863 Medium
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135177 - Incorrect Authorization
CVE-2026-11379
CWE-863 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135178 - Information Exposure Through Log Files
CVE-2026-8330
CWE-532 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135179 - Improper input validation
CVE-2026-1606
CWE-20 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135180 - Incorrect Authorization
CVE-2026-5952
CWE-863 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135181 - Improper Access Control
CVE-2026-5796
CWE-284 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135182 - Improper Access Control
CVE-2026-0934
CWE-284 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135183 - Missing Authorization
CVE-2026-3176
CWE-862 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU135184 - Server-Side Request Forgery (SSRF)
CVE-2026-12635
CWE-918 Low
No
No
18.11.6, 19.0.3, 19.1.1 25.06.2026 SB2026062554
#VU134372 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-10087
CWE-79 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134373 - Improper input validation
CVE-2026-7250
CWE-20 Medium
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134374 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-8589
CWE-79 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134375 - Resource exhaustion
CVE-2026-1500
CWE-400 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134379 - Improper Access Control
CVE-2026-6277
CWE-284 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168


Showing elements 41 - 60 out of 1052