Known vulnerabilities in GitLab Enterprise Edition - page 4

Software CPE: cpe:2.3:a:gitlab:gitlab-ee:*:*:*:*:*:*:*:*
Total vulnerabilities: 1052
Public exploits: 16
Known exploited (KEV): 4
Highest CVSSv4 Score: 9.3

Breakdown by Severity Chart

Severity distribution of vulnerabilities affecting GitLab Enterprise Edition GitLab Enterprise Edition is affected by 1052 known vulnerabilities: 1 critical, 31 high, 481 medium, 539 low Critical High Medium Low

Vulnerabilities (1052)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU134371 - Improper Access Control
CVE-2026-6552
CWE-284 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134376 - Improper Access Control
CVE-2026-6269
CWE-284 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134377 - Server-Side Request Forgery (SSRF)
CVE-2026-9204
CWE-918 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134378 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-10733
CWE-79 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134380 - Improper input validation
CVE-2026-6976
CWE-20 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134381 - Improper Access Control
CVE-2026-3553
CWE-284 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU134382 - Improper Encoding or Escaping of Output
CVE-2026-9694
CWE-116 Low
No
No
18.10.8, 18.11.5, 19.0.2 11.06.2026 SB2026061168
#VU132677 - Use of Incorrectly-Resolved Name or Reference
CVE-2026-8716
CWE-706 Medium
No
No
18.10.7, 18.11.4, 19.0.1 28.05.2026 SB20260528265
#VU132676 - Missing Authorization
CVE-2026-2601
CWE-862 Medium
No
No
18.10.7, 18.11.4, 19.0.1 28.05.2026 SB20260528265
#VU132675 - Missing Authorization
CVE-2026-5296
CWE-862 Medium
No
No
18.10.7, 18.11.4, 19.0.1 28.05.2026 SB20260528265
#VU132674 - Incorrect Authorization
CVE-2026-6713
CWE-863 Medium
No
No
18.10.7, 18.11.4, 19.0.1 28.05.2026 SB20260528265
#VU132673 - Allocation of Resources Without Limits or Throttling
CVE-2026-1402
CWE-770 Medium
No
No
18.10.7, 18.11.4, 19.0.1 28.05.2026 SB20260528265
#VU132672 - Authorization Bypass Through User-Controlled Key
CVE-2026-4868
CWE-639 Medium
No
No
18.10.7, 18.11.4, 19.0.1 28.05.2026 SB20260528265
#VU131678 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-6335
CWE-79 Low
No
No
18.11.3 18.05.2026 SB2026051863
#VU131680 - Improper Access Control
CVE-2026-3607
CWE-284 Low
No
No
18.9.7, 18.10.6, 18.11.3 18.05.2026 SB2026051863
#VU131685 - Improper Authorization
CVE-2026-3073
CWE-285 Low
No
No
18.9.7, 18.10.6, 18.11.3 18.05.2026 SB2026051863
#VU131686 - Improper Access Control
CVE-2025-13874
CWE-284 Low
No
No
18.9.7, 18.10.6, 18.11.3 18.05.2026 SB2026051863
#VU131687 - Server-Side Request Forgery (SSRF)
CVE-2026-7471
CWE-918 Low
No
No
18.9.7, 18.10.6, 18.11.3 18.05.2026 SB2026051863
#VU131688 - Missing Authorization
CVE-2026-2900
CWE-862 Low
No
No
18.9.7, 18.10.6, 18.11.3 18.05.2026 SB2026051863
#VU131689 - Improper Authorization
CVE-2026-6883
CWE-285 Low
No
No
18.9.7, 18.10.6, 18.11.3 18.05.2026 SB2026051863


Showing elements 61 - 80 out of 1052