CVE-2026-34242
- EPSS 0.41%
- Veröffentlicht 15.04.2026 18:19:59
- Zuletzt bearbeitet 21.04.2026 14:07:49
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
- EPSS 0.24%
- Veröffentlicht 15.04.2026 18:15:12
- Zuletzt bearbeitet 21.04.2026 14:09:48
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.
- EPSS 0.71%
- Veröffentlicht 15.04.2026 18:13:07
- Zuletzt bearbeitet 21.04.2026 14:10:08
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5....
CVE-2026-33220
- EPSS 0.32%
- Veröffentlicht 15.04.2026 18:03:40
- Zuletzt bearbeitet 21.04.2026 14:10:42
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to u...
CVE-2026-33214
- EPSS 0.24%
- Veröffentlicht 15.04.2026 17:51:46
- Zuletzt bearbeitet 21.04.2026 14:11:09
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update...
CVE-2026-33212
- EPSS 0.22%
- Veröffentlicht 15.04.2026 17:48:17
- Zuletzt bearbeitet 21.04.2026 14:11:21
Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brut...
CVE-2026-27457
- EPSS 0.3%
- Veröffentlicht 26.02.2026 21:56:03
- Zuletzt bearbeitet 27.02.2026 17:05:12
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This ...
CVE-2026-24126
- EPSS 0.45%
- Veröffentlicht 18.02.2026 23:05:03
- Zuletzt bearbeitet 19.02.2026 18:34:57
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workar...
CVE-2026-21889
- EPSS 0.32%
- Veröffentlicht 14.01.2026 16:28:30
- Zuletzt bearbeitet 23.01.2026 14:49:52
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This...
CVE-2025-68398
- EPSS 0.49%
- Veröffentlicht 18.12.2025 23:00:57
- Zuletzt bearbeitet 06.02.2026 20:16:08
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.