CVE-2026-44263
published 2026-05-07CVE-2026-44263: Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations…
PriorityP425medium4.3CVSS 3.1
AVNACLPRLUINSUCLINAN
EPSS
0.29%
21.6th percentile
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17.1 | 5.17.1 |
| weblate | weblate | >= 0 < 5.17.1 | 5.17.1 |
| weblateorg | weblate | < 5.17.1 | 5.17.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
ghsa·2026-05-07
CVE-2026-44263 [MEDIUM] CWE-203 Weblate Vulnerable to Private Translation Enumeration via Screenshot API
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
### Impact
The screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user.
### Patches
* https://github.com/WeblateOrg/weblate/pull/19258
### Acknowledgement
Weblate thanks Luay for reporting this vulnerability according to the organization's [security issues guideline](https://docs.weblate.org/en/latest/security/issues.html).
VulDB
weblate up to 5.17.0 information exposure
vuldb·2026-05-07·CVSS 4.3
CVE-2026-44263 [MEDIUM] weblate up to 5.17.0 information exposure
A vulnerability categorized as problematic has been discovered in weblate up to 5.17.0. This affects an unknown part. Such manipulation leads to information exposure through discrepancy.
This vulnerability is referenced as CVE-2026-44263. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-07
Published