Vulnerabilities > Gitlab > Gitlab > 10.6.2

DATE CVE VULNERABILITY TITLE RISK
2018-04-05 CVE-2018-9244 Cross-site Scripting vulnerability in Gitlab
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature).
network
gitlab CWE-79
4.3
2018-04-05 CVE-2018-9243 Cross-site Scripting vulnerability in Gitlab
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests).
network
gitlab CWE-79
4.3