<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 18:39:44 +0000</lastBuildDate>
    <item>
      <title>BIT-gitlab-2024-4201 — Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab</title>
      <link>https://cve.radiocsirt.org/vuln/bit-gitlab-2024-4201</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Bitnami: gitlab&lt;/p&gt;
&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bit-gitlab-2024-4201</guid>
    </item>
    <item>
      <title>certfr-2024-avi-0490 — De multiples vulnérabilités ont été découvertes dans GitLab. Elles permettent à un attaquant de provoquer un déni de se…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2024-avi-0490</link>
      <description>certfr-2024-avi-0490</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2024-avi-0490</guid>
    </item>
    <item>
      <title>EUVD-2026-160598</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-160598</link>
      <description>EUVD-2026-160598</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-160598</guid>
    </item>
    <item>
      <title>fkie_cve-2024-4201</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2024-4201</link>
      <description>&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2024-4201</guid>
    </item>
    <item>
      <title>GHSA-wq8m-964x-6vr4</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-wq8m-964x-6vr4</link>
      <description>&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-wq8m-964x-6vr4</guid>
    </item>
    <item>
      <title>gsd-2024-4201</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2024-4201</link>
      <description>gsd-2024-4201</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2024-4201</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2024-4201</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4201</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:16.04:LTS: gitlab&lt;/p&gt;
&lt;p&gt;A cross-site scripting issue has been discovered in GitLab affecting all versions starting from 5.1 before 16.10.7, all versions starting from 16.11 before 16.111.4, all versions starting from 17.0 before 17.0.2. When viewing an XML file in a repository in raw mode, it can be made to render as HTML if viewed under specific circumstances.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2024-4201</guid>
    </item>
    <item>
      <title>WID-SEC-W-2024-1367 — GitLab: Mehrere Schwachstellen ermöglichen Denial of Service und Cross-Site Scripting</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1367</link>
      <description>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um einen Denial of Service Angriff durchzuführen und einen Cross-Site-Scripting-Angriff zu starten.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in GitLab ausnutzen, um einen Denial of Service Angriff durchzuführen und einen Cross-Site-Scripting-Angriff zu starten.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2024-1367</guid>
    </item>
  </channel>
</rss>
