Weblateorg Weblate vulnerabilities
42 known vulnerabilities affecting weblateorg/weblate.
Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH8MEDIUM27LOW4
Vulnerabilities
Page 1 of 3
CVE-2022-23915P3HIGHCVSS 8.8v>= 4.11.1, < 2026.82022-03-04
CVE-2022-23915 [HIGH] CWE-88 CVE-2022-23915: The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argum
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
nvd
CVE-2025-64725P3CRITICALCVSS 9.8fixed in 5.152025-12-15
CVE-2025-64725 [CRITICAL] CWE-286 CVE-2025-64725: Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an in
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.
nvd
CVE-2026-34393P3HIGHCVSS 8.8fixed in 5.172026-04-15
CVE-2026-34393 [HIGH] CWE-269 CVE-2026-34393: Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.
nvd
CVE-2025-68398P3CRITICALCVSS 9.1fixed in 5.15.12025-12-18
CVE-2025-68398 [CRITICAL] CWE-20 CVE-2025-68398: Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.
nvd
CVE-2026-24126P3CRITICALCVSS 9.1fixed in 5.16.02026-02-19
CVE-2026-24126 [CRITICAL] CWE-88 CVE-2026-24126: Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not valida
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access to the management console.
nvd
CVE-2026-41654P3HIGHCVSS 8.1fixed in 5.17.12026-05-07
CVE-2026-41654 [HIGH] CWE-20 CVE-2026-41654: Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with projec
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0
nvd
CVE-2026-55228P3HIGHCVSS 8.1fixed in 2026.72026-08-26
CVE-2026-55228 [HIGH] CWE-639 CVE-2026-55228: Weblate is a web-based continuous localization platform used to manage software translations. In ver
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did not properly enforce the scope of project- and workspace-scoped teams, allowing a user to submit invalid team configurations through the API. By assigning projects to a team via these unvalidated requests, a user
nvd
CVE-2026-33435P3HIGHCVSS 8.0fixed in 5.172026-04-15
CVE-2026-33435 [HIGH] CWE-23 CVE-2026-33435: Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filte
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can limit the scope of the vulnerability by res
nvd
CVE-2026-21889P3HIGHCVSS 7.5fixed in 5.15.22026-01-14
CVE-2026-21889 [HIGH] CWE-284 CVE-2026-21889: Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directl
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in 5.15.2.
nvd
CVE-2026-34242P3HIGHCVSS 7.7fixed in 2026.72026-04-15
CVE-2026-34242 [HIGH] CWE-22 CVE-2026-34242: Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.
nvd
CVE-2025-32021P3HIGHCVSS 7.5fixed in 5.112025-04-15
CVE-2025-32021 [HIGH] CWE-598 CVE-2025-32021: Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confident
nvd
CVE-2025-68279P3MEDIUMCVSS 6.5fixed in 5.15.12025-12-18
CVE-2025-68279 [MEDIUM] CWE-22 CVE-2025-68279: Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbit
Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.
nvd
CVE-2026-62326P3MEDIUMCVSS 6.5fixed in 2026.72026-08-26
CVE-2026-62326 [MEDIUM] CWE-400 CVE-2026-62326: Weblate is a web-based continuous localization platform used to manage software translations. In ver
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a user with the built-in "Edit source" role can store a malicious regular expression in a source string's flags that is executed without any timeout, allowing them to stall requests and deny service. Regular expressions supplied
nvd
CVE-2026-33220P3MEDIUMCVSS 6.8fixed in 5.172026-04-15
CVE-2026-33220 [MEDIUM] CWE-22 CVE-2026-33220: Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API expo
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.
nvd
CVE-2026-50127P4MEDIUMCVSS 5.9v>= 5.15, < 2026.62026-06-10
CVE-2026-50127 [MEDIUM] CWE-918 CVE-2026-50127: Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private range restrictions. This issue has been patched in version 2026.6.
nvd
CVE-2026-41519P4MEDIUMCVSS 5.4fixed in 5.17.12026-05-07
CVE-2026-41519 [MEDIUM] CWE-613 CVE-2026-41519: Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their passwor
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1.
nvd
CVE-2025-58352P4MEDIUMCVSS 6.5fixed in 5.13.12025-09-05
CVE-2025-58352 [MEDIUM] CWE-613 CVE-2025-58352: Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that ca
Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in version 5.13.1.
nvd
CVE-2026-77507P4MEDIUMCVSS 5.3fixed in 2026.82026-08-26
CVE-2026-77507 [MEDIUM] CWE-200 CVE-2026-77507: Weblate is a web-based continuous localization platform used to manage software translations. In ver
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, Weblate's object-scoped RSS feeds do not apply the permission checks used elsewhere, allowing unauthorized users to read change-history metadata from private projects and restricted components. On installations that permit anony
nvd
CVE-2026-34244P4MEDIUMCVSS 5.0fixed in 5172026-04-15
CVE-2026-34244 [MEDIUM] CWE-200 CVE-2026-34244: Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit pe
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request to the attacker-controlled URL
nvd
CVE-2024-39303P4MEDIUMCVSS 5.4v>= 4.14, < 5.6.22024-07-01
CVE-2024-39303 [MEDIUM] CWE-73 CVE-2024-39303: Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate
Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. This issue has been addressed in Weblate 5.6.2. As a workaround, do not allow untrusted users to create projects.
nvd
1 / 3Next →