3.5

CVSS3.1

CVE-2025-12734 - Improper Encoding or Escaping of Output in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.6 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to, under certain conditions, render content in dialogs to other users by injecting malicious HTML content into mer…

πŸ“… Published: Dec. 11, 2025, 7:32 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:02 p.m.

8.5

CVSS3.1

CVE-2025-67738 -

squid/cachemgr.cgi in Webmin before 2.600 does not properly quote arguments. This is relevant if Webmin's Squid module and its Cache Manager feature are available, and an untrusted party is able to authenticate to Webmin and has certain Cache Manager permissions (the "cms" security option).

πŸ“… Published: Dec. 11, 2025, 6:34 a.m. πŸ”„ Last Modified: April 15, 2026, 12:35 a.m.

6.5

CVSS3.1

CVE-2025-4097 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a denial of service condition by uploading specially crafted images.

πŸ“… Published: Dec. 11, 2025, 4:05 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:01 p.m.

7.7

CVSS3.1

CVE-2025-8405 - Improper Encoding or Escaping of Output in GitLab

GitLab has remediated a security issue in GitLab CE/EE affecting all versions from 17.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to perform unauthorized actions on behalf of other users by injecting malicious HTML into vulnerability cod…

πŸ“… Published: Dec. 11, 2025, 4:05 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

4.3

CVSS3.1

CVE-2025-11247 - Authorization Bypass Through User-Controlled Key in GitLab

GitLab has remediated an issue in GitLab EE affecting all versions from 13.2 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to disclose sensitive information from private projects by executing specifically crafted GraphQL queries.

πŸ“… Published: Dec. 11, 2025, 4:04 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:05 p.m.

6.8

CVSS3.1

CVE-2025-11984 - Authentication Bypass Using an Alternate Path or Channel in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 13.1 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to bypass WebAuthn two-factor authentication by manipulating the session state under certain conditions.

πŸ“… Published: Dec. 11, 2025, 4:04 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

7.5

CVSS3.1

CVE-2025-12562 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 11.10 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an unauthenticated user to create a denial of service condition by sending crafted GraphQL queries that bypass query complexity limits.

πŸ“… Published: Dec. 11, 2025, 3:33 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9 p.m.

8.7

CVSS3.1

CVE-2025-12716 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.4 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that, under certain conditions could have allowed an authenticated user to perform unauthorized actions on behalf of another user by creating wiki pages with mal…

πŸ“… Published: Dec. 11, 2025, 3:33 a.m. πŸ”„ Last Modified: Feb. 26, 2026, 4:21 p.m.

4.3

CVSS3.1

CVE-2025-13978 - Generation of Error Message Containing Sensitive Information in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.5 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to discover the names of private projects they do not have access through API requests.

πŸ“… Published: Dec. 11, 2025, 3:33 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:03 p.m.

6.5

CVSS3.1

CVE-2025-14157 - Allocation of Resources Without Limits or Throttling in GitLab

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 6.3 before 18.4.6, 18.5 before 18.5.4, and 18.6 before 18.6.2 that could have allowed an authenticated user to cause a Denial of Service condition by sending crafted API calls with large content parameters.

πŸ“… Published: Dec. 11, 2025, 3:33 a.m. πŸ”„ Last Modified: Dec. 23, 2025, 9:05 p.m.
Total resulsts: 345302
Page 2277 of 34,531
Β« previous page Β» next page
Filters