CVEs affecting projects tracked on Release Alert, from NVD & OSV.
GitLab EE 11.0 and later through 12.7.2 allows XSS.