What is CVE-2026-15216?
CVE-2026-15216 is a cross-site scripting (XSS) vulnerability in GitLab CE/EE. Due to improper neutralization of user-controlled data in pagination controls, an attacker could potentially execute malicious scripts under certain conditions. Affected versions should be updated immediately to 19.0.6, 19.1.4, 19.2.2, or later.
Azərbaycanca: CVE-2026-15216 GitLab CE/EE versiyalarında cross-site scripting (XSS) boşluğudur. Təsirə məruz qalan versiyalarda pagination idarəetmələrində istifadəçi məlumatlarının düzgün neytrallaşdırılmaması səbəbindən uzaqdan kod icrası mümkündür. Təsirə məruz qalan sistemləri dərhal 19.0.6, 19.1.4, 19.2.2 və ya daha yuxarı versiyalara yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: GitLab
FAQ2
What software is affected by CVE-2026-15216?
CVE-2026-15216 affects GitLab Community Edition (CE) and Enterprise Edition (EE).
Which versions should be updated to patch CVE-2026-15216?
It is recommended to update affected systems to versions 19.0.6, 19.1.4, 19.2.2, or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.