← All credits
Thanks [joaxcar](https://hackerone.com/joaxcar) for reporting this vulnerability through our HackerOne bug bounty program
104 vulnerability records and advisories credit this contributor.
CVE-2025-0362
Improper Restriction of Rendered UI Layers or Frames in GitLab
CVE-2024-9773
Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
CVE-2024-8977
Server-Side Request Forgery (SSRF) in GitLab
CVE-2024-8648
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2024-8647
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
CVE-2024-8640
Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
CVE-2024-8402
Improper Neutralization of Special Elements used in a Command ('Command Injection') in GitLab
CVE-2024-8312
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2024-8186
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2024-8180
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab