← All credits
Thanks [yvvdwf](https://hackerone.com/yvvdwf) for reporting this vulnerability through our HackerOne bug bounty program
52 vulnerability records and advisories credit this contributor.
CVE-2023-6371
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2023-6159
Inefficient Regular Expression Complexity in GitLab
CVE-2023-6033
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
CVE-2023-5933
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) in GitLab
CVE-2023-5600
Missing Authorization in GitLab
CVE-2023-5356
Incorrect Authorization in GitLab
CVE-2023-2478
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.9.7, all versions starting from 15.10 before 15.10.6, all versions starting from 15.11 before 15.11.2. Under certain conditions, a malicious unauthorized GitL
CVE-2023-2442
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A specially crafted merge request could lead to a stored XSS on the client side which allows attackers t
CVE-2023-2232
An issue has been discovered in GitLab affecting all versions starting from 15.10 before 16.1, leading to a ReDoS vulnerability in the Jira prefix
CVE-2022-4092
An issue has been discovered in GitLab EE affecting all versions starting from 15.6 before 15.6.1. It was possible to create a malicious README page due to improper neutralisation of user supplied input.