WeblateOrg / Weblate
43 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2026-86035 | Weblate: Mercurial argument injection via repository filenames allows authenticated command execution | HIGH | 8.5 | Sep 29, 2026 |
| CVE-2026-77573 | Weblate: DNS rebinding in VCS operations allows server-side request forgery | LOW | 3.5 | Aug 26, 2026 |
| CVE-2026-77507 | Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users | MEDIUM | 5.3 | Aug 26, 2026 |
| CVE-2026-62326 | Weblate Has Uncontrolled Resource Consumption via | MEDIUM | 6.5 | Aug 26, 2026 |
| CVE-2026-62249 | Weblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpoint | MEDIUM | 4.3 | Aug 26, 2026 |
| CVE-2026-61792 | Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242) | HIGH | 7.7 | Aug 26, 2026 |
| CVE-2026-61790 | Weblate: Team-enforced 2FA is bypassed for global permissions | MEDIUM | 4.4 | Aug 26, 2026 |
| CVE-2026-55228 | Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project | HIGH | 8.1 | Aug 26, 2026 |
| CVE-2026-55227 | Observable object existence disclosure in private Weblate projects via globally scoped object lookups | MEDIUM | 4.3 | Aug 26, 2026 |
| CVE-2026-77508 | Weblate: Unverified REST API email changes | LOW | 3.5 | Aug 26, 2026 |
| CVE-2026-45106 | Weblate: Stored HTML injection in editor search preview | MEDIUM | 4.6 | Jun 10, 2026 |
| CVE-2026-50127 | Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96) | MEDIUM | 5.9 | Jun 10, 2026 |
| CVE-2026-44264 | Weblate is vulnerable to XSS via crafted Markdown | MEDIUM | 4.3 | May 7, 2026 |
| CVE-2026-44263 | Weblate: Private Translation Enumeration via Screenshot API | MEDIUM | 4.3 | May 7, 2026 |
| CVE-2026-41519 | Weblate's API Token Not Invalidated on Password Change | MEDIUM | 5.4 | May 7, 2026 |
| CVE-2026-41654 | Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url | MEDIUM | 5.3 | May 7, 2026 |
| CVE-2026-40256 | Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision | MEDIUM | 5.0 | Apr 15, 2026 |
| CVE-2026-39845 | Weblate: SSRF via the webhook add-on using unprotected fetch_url() | MEDIUM | 4.1 | Apr 15, 2026 |
| CVE-2026-34393 | Weblate: Privilege escalation in the user API endpoint | HIGH | 8.8 | Apr 15, 2026 |
| CVE-2026-34244 | Weblate: SSRF via Project-Level Machinery Configuration | MEDIUM | 5.0 | Apr 15, 2026 |
| CVE-2026-34242 | Weblate: Arbitrary File Read via Symlink | HIGH | 7.7 | Apr 15, 2026 |
| CVE-2026-33440 | Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads | MEDIUM | 5.0 | Apr 15, 2026 |
| CVE-2026-33435 | Weblate: Remote code execution during backup restoration | HIGH | 8.1 | Apr 15, 2026 |
| CVE-2026-33220 | Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository | MEDIUM | 6.8 | Apr 15, 2026 |
| CVE-2026-33214 | Weblate has improper access control for the translation memory API | MEDIUM | 4.3 | Apr 15, 2026 |
Showing 1 to 25 of 43 CVEs