Weblate

Weblate

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 15.04.2026 18:36:44
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is...

  • EPSS 0.01%
  • Veröffentlicht 15.04.2026 18:26:51
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook...

  • EPSS 0.04%
  • Veröffentlicht 15.04.2026 18:24:30
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.

  • EPSS 0.03%
  • Veröffentlicht 15.04.2026 18:22:42
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addr...

  • EPSS 0.01%
  • Veröffentlicht 15.04.2026 18:19:59
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.

  • EPSS 0.33%
  • Veröffentlicht 15.04.2026 18:13:07
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5....

  • EPSS 0.04%
  • Veröffentlicht 15.04.2026 18:03:40
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to u...

  • EPSS 0.01%
  • Veröffentlicht 15.04.2026 17:51:46
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update...

  • EPSS 0.03%
  • Veröffentlicht 15.04.2026 17:48:17
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brut...

  • EPSS 0.03%
  • Veröffentlicht 26.02.2026 21:56:03
  • Zuletzt bearbeitet 27.02.2026 17:05:12

Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This ...