CVE-2026-86035
- EPSS 0.37%
- Veröffentlicht 29.09.2026 15:17:30
- Zuletzt bearbeitet 02.10.2026 13:18:01
Weblate is a web-based continuous localization platform used to manage software translations. Weblate 4.11.1 through 2026.7.1 contains an argument-injection vulnerability in its Mercurial backend. Repository filenames beginning with - could be interp...
CVE-2026-77573
- EPSS 0.14%
- Veröffentlicht 26.08.2026 20:48:48
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through ...
CVE-2026-77507
- EPSS 0.24%
- Veröffentlicht 26.08.2026 20:45:23
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change...
CVE-2026-62326
- EPSS 0.25%
- Veröffentlicht 26.08.2026 20:36:25
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is execute...
CVE-2026-62249
- EPSS 0.18%
- Veröffentlicht 26.08.2026 20:29:49
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that project through...
CVE-2026-61792
- EPSS 0.32%
- Veröffentlicht 26.08.2026 20:26:27
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a project administrator can read files outside their repository through the App store metadata download feature, which resolves...
CVE-2026-61790
- EPSS 0.25%
- Veröffentlicht 26.08.2026 20:23:53
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this require...
CVE-2026-55228
- EPSS 0.23%
- Veröffentlicht 26.08.2026 20:14:02
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team ...
CVE-2026-55227
- EPSS 0.18%
- Veröffentlicht 26.08.2026 20:10:39
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 40...
CVE-2026-77508
- EPSS 0.15%
- Veröffentlicht 26.08.2026 19:56:59
- Zuletzt bearbeitet 09.09.2026 21:09:13
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for th...