AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-15216

HIGH · CVSS 8.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-12 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

GitLab CE/EE versions prior to 19.0.6, 19.1.4, and 19.2.2 are vulnerable to cross-site scripting due to inadequate handling of user-controlled data in pagination controls within the analytics dashboard. This flaw could allow attackers to execute arbitrary scripts in the context of a user's session, potentially leading to data theft or session hijacking. Organizations using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-15216
Severity
HIGH
CVSS
8.7
EPSS
0.26%
GitLab

Original NVD Description

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 19.0.6, 19.1 before 19.1.4, and 19.2 before 19.2.2 that under certain conditions could have allowed cross-site scripting due to improper neutralization of user-controlled data rendered in pagination controls by an analytics dashboard component.