CVE-2020-10078: GitLab

Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.

GitLab 12.1 through 12.8.1 allows XSS. The merge request submission form was determined to have a stored cross-site scripting vulnerability.

Affected products

  • GitLab GitLab: from 12.1.0, up to and including 12.8.1

Published 2020-03-13. Last modified 2026-06-17.