Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4355 articles · 196337 vulns · 36/41 feeds (7d)
← Back to list
8.7
CVE-2026-15217PATCHED
gitlab · gitlab

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab

Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled values rendered in table cell content by an analytics dashboard component.

Affected Products

VendorProductVersions
gitlabgitlab18.2, 19.1, 19.2

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
open sourcegitlabcert_advisory90%

References

  • https://gitlab.com/gitlab-org/gitlab/-/work_items/605449
  • https://hackerone.com/reports/3830478(technical-description, exploit, permissions-required)
  • https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-released/

Related News (3 articles)

Tier B
BSI Advisories10d ago
[NEU] [hoch] GitLab: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR11d ago
Multiples vulnérabilités dans GitLab (13 août 2026)
→ No new info (linked only)
Tier C
VulDB11d ago
CVE-2026-15217 | GitLab up to 19.0.5/19.1.3/19.2.1 Analytics Dashboard cross site scripting
→ No new info (linked only)
CVSS 3.18.7 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited❌ No
Patch available
19.0.619.1.419.2.2
CWECWE-79
PublishedAug 12, 2026
Trending Score14
Source articles3
Independent3
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-19478
Improper Control of Generation of Code ('Code Injection') in GitLab
Trending: 71
HIGHCVE-2026-19650
Cross-Site Request Forgery (CSRF) in GitLab
Trending: 34
HIGHCVE-2026-10053
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in GitLab
Trending: 25
HIGHCVE-2026-15216
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 14
HIGHCVE-2026-16627
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in GitLab
Trending: 14

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 12, 2026
Discovered by ZDM
Aug 12, 2026
Patch Available
Aug 13, 2026