CVE-2026-45106
- EPSS 0.21%
- Veröffentlicht 10.06.2026 19:56:49
- Zuletzt bearbeitet 10.06.2026 20:21:20
Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the aut...
CVE-2026-50127
- EPSS 0.29%
- Veröffentlicht 10.06.2026 19:56:37
- Zuletzt bearbeitet 10.06.2026 20:21:20
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some...
CVE-2026-44264
- EPSS 0.28%
- Veröffentlicht 07.05.2026 13:43:30
- Zuletzt bearbeitet 11.05.2026 14:50:31
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1.
CVE-2026-44263
- EPSS 0.29%
- Veröffentlicht 07.05.2026 13:42:46
- Zuletzt bearbeitet 11.05.2026 17:24:45
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1.
CVE-2026-41519
- EPSS 0.23%
- Veröffentlicht 07.05.2026 13:41:43
- Zuletzt bearbeitet 11.05.2026 17:00:55
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revo...
CVE-2026-41654
- EPSS 0.37%
- Veröffentlicht 07.05.2026 13:40:12
- Zuletzt bearbeitet 11.05.2026 15:30:11
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose ...
- EPSS 0.32%
- Veröffentlicht 15.04.2026 18:36:44
- Zuletzt bearbeitet 21.04.2026 14:02:00
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is...
CVE-2026-39845
- EPSS 0.28%
- Veröffentlicht 15.04.2026 18:26:51
- Zuletzt bearbeitet 21.04.2026 14:05:02
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook...
CVE-2026-34393
- EPSS 0.39%
- Veröffentlicht 15.04.2026 18:24:30
- Zuletzt bearbeitet 21.04.2026 14:05:57
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
- EPSS 0.24%
- Veröffentlicht 15.04.2026 18:22:42
- Zuletzt bearbeitet 21.04.2026 14:06:32
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addr...