cbcvebase.

Weblate vulnerabilities

38 known vulnerabilities affecting weblate/weblate.

Total CVEs
38
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH9MEDIUM24LOW2

Vulnerabilities

Page 1 of 2
CVE-2022-23915P3HIGHCVSS 8.8fixed in 4.11.12022-03-04
CVE-2022-23915 [HIGH] CWE-88 CVE-2022-23915: The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argum The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
ghsanvdosv
CVE-2025-64725P3CRITICALCVSS 9.8fixed in 5.152025-12-15
CVE-2025-64725 [CRITICAL] CWE-286 CVE-2025-64725: Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an in Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.
ghsanvdosv
CVE-2026-34393P3HIGHCVSS 8.8fixed in 5.172026-04-15
CVE-2026-34393 [HIGH] CWE-269 CVE-2026-34393: Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
ghsanvd
CVE-2025-68398P3CRITICALCVSS 9.1fixed in 5.15.12025-12-18
CVE-2025-68398 [CRITICAL] CWE-20 CVE-2025-68398: Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
ghsanvdosv
CVE-2026-24126P3CRITICALCVSS 9.1fixed in 5.162026-02-19
CVE-2026-24126 [CRITICAL] CWE-88 CVE-2026-24126: Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not valida Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.
ghsanvdosv
CVE-2026-41654P3HIGHCVSS 8.1fixed in 5.17.12026-05-07
CVE-2026-41654 [HIGH] CWE-20 CVE-2026-41654: Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with projec Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0
ghsanvd
CVE-2026-33435P3HIGHCVSS 8.0fixed in 5.172026-04-15
CVE-2026-33435 [HIGH] CWE-23 CVE-2026-33435: Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filte Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by res
ghsanvd
CVE-2026-55228P3HIGH≥ 0, < 2026.72026-08-28
CVE-2026-55228 [HIGH] CWE-639 Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project ### Impact The API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. ### Patches * http
ghsa
CVE-2026-21889P3HIGHCVSS 7.5fixed in 5.15.22026-01-14
CVE-2026-21889 [HIGH] CWE-284 CVE-2026-21889: Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directl Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
ghsanvdosv
CVE-2026-34242P3HIGHCVSS 7.7fixed in 5.172026-04-15
CVE-2026-34242 [HIGH] CWE-22 CVE-2026-34242: Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
ghsanvd
CVE-2025-32021P3HIGHCVSS 7.5fixed in 5.112025-04-15
CVE-2025-32021 [HIGH] CWE-598 CVE-2025-32021: Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confident
ghsanvdosv
CVE-2025-68279P3MEDIUMCVSS 6.5fixed in 5.15.12025-12-18
CVE-2025-68279 [MEDIUM] CWE-22 CVE-2025-68279: Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbit Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
ghsanvdosv
CVE-2026-33220P3MEDIUMCVSS 6.8fixed in 5.172026-04-15
CVE-2026-33220 [MEDIUM] CWE-22 CVE-2026-33220: Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API expo Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.
ghsanvd
CVE-2026-41519P4MEDIUMCVSS 5.4fixed in 5.17.12026-05-07
CVE-2026-41519 [MEDIUM] CWE-613 CVE-2026-41519: Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their passwor Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1.
ghsanvd
CVE-2025-58352P4MEDIUMCVSS 6.5fixed in 5.13.12025-09-05
CVE-2025-58352 [MEDIUM] CWE-613 CVE-2025-58352: Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that ca Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
ghsanvdosv
CVE-2026-34244P4MEDIUMCVSS 5.0fixed in 5.172026-04-15
CVE-2026-34244 [MEDIUM] CWE-200 CVE-2026-34244: Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit pe Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request to the attacker-controlled URL
ghsanvd
CVE-2026-50127P4MEDIUM≥ 5.15, < 2026.62026-07-07
CVE-2026-50127 [MEDIUM] CWE-918 Weblate SSRF: outbound URL guard misses some private ranges Weblate SSRF: outbound URL guard misses some private ranges ### Impact Weblate's `VCS_RESTRICT_PRIVATE` did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. ### Patches * https://github.com/WeblateOrg/weblate/pull/19768 ### Resources The issue was reported by @tonghuaroot
ghsa
CVE-2017-5537P4MEDIUMCVSS 5.3≤ 2.102017-03-15
CVE-2017-5537 [MEDIUM] CWE-200 CVE-2017-5537: The password reset form in Weblate before 2.10.1 provides different error messages depending on whet The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.
ghsanvdosv
CVE-2024-39303P4MEDIUMCVSS 5.4≥ 4.14, < 5.6.22024-07-01
CVE-2024-39303 [MEDIUM] CWE-73 CVE-2024-39303: Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaround, do not allow untrusted users to create projects.
ghsanvdosv
CVE-2025-67492P4MEDIUMCVSS 5.3fixed in 5.152025-12-16
CVE-2025-67492 [MEDIUM] CWE-1286 CVE-2025-67492: Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repo Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability.
ghsanvdosv
Weblate vulnerabilities | cvebase