Launchpad.net

CVE 2019-19311

GitLab EE 8.14 through 12.5, 12.4.3, and 12.3.6 allows XSS in group and profile fields.

See the CVE page on Mitre.org for more details.