CVE-2026-44264
published 2026-05-07CVE-2026-44264: Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly…
PriorityP422medium4.3CVSS 3.1
AVNACLPRLUINSUCNILAN
EPSS
0.27%
20.1th percentile
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.17.1 | 5.17.1 |
| weblate | weblate | >= 0 < 5.17.1 | 5.17.1 |
| weblateorg | weblate | < 5.17.1 | 5.17.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate vulnerable to XSS via crafted Markdown
ghsa·2026-05-07
CVE-2026-44264 [MEDIUM] CWE-79 Weblate vulnerable to XSS via crafted Markdown
Weblate vulnerable to XSS via crafted Markdown
### Impact
The Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes.
### Patches
* https://github.com/WeblateOrg/weblate/pull/19259
### Workarounds
Even though the attacker might be able to inject code into the HTML, the Weblate's strict CSP should mitigate the risks.
### Acknowlegement
Michal Čihař has identified and fixed this vulnerability.
VulDB
weblate up to 5.17.0 cross site scripting
vuldb·2026-05-07·CVSS 4.3
CVE-2026-44264 [MEDIUM] weblate up to 5.17.0 cross site scripting
A vulnerability identified as problematic has been detected in weblate up to 5.17.0. This vulnerability affects unknown code. Performing a manipulation results in basic cross site scripting.
This vulnerability is identified as CVE-2026-44264. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-07
Published