CVE-2018-18643: GitLab

Medium severity, CVSS 6.1. EPSS: 1.2% chance of exploitation in the next 30 days.

GitLab CE & EE 11.2 and later and before 11.5.0-rc12, 11.4.6, and 11.3.10 have Persistent XSS.

Affected products

  • GitLab GitLab: up to and including 11.2.0; from 11.3.0, before 11.3.10 (fixed in 11.3.10); from 11.4.0, before 11.4.6 (fixed in 11.4.6); from 11.4.7, up to and including 11.4.9; version 11.5.0 only

Published 2019-04-25. Last modified 2026-06-17.