Weblateorg Weblate vulnerabilities
42 known vulnerabilities affecting weblateorg/weblate.
Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH8MEDIUM27LOW4
Vulnerabilities
Page 2 of 3
CVE-2025-67492P4MEDIUMCVSS 5.3fixed in 5.152025-12-16
CVE-2025-67492 [MEDIUM] CWE-1286 CVE-2025-67492: Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repo
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability.
nvd
CVE-2026-40256P4MEDIUMCVSS 5.0fixed in 5.172026-04-15
CVE-2026-40256 [MEDIUM] CWE-22 CVE-2026-40256: Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the
nvd
CVE-2025-66407P4MEDIUMCVSS 5.0fixed in 5.152025-12-16
CVE-2025-66407 [MEDIUM] CWE-352 CVE-2025-66407: Weblate is a web based localization tool. The Create Component functionality in Weblate allows autho
Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, prior to version 5.15, the repository URL field is not validated or sanitized, allowing an attacker to su
nvd
CVE-2025-47951P4MEDIUMCVSS 4.9fixed in 5.122025-06-16
CVE-2025-47951 [MEDIUM] CWE-307 CVE-2025-47951: Weblate is a web based localization tool. Prior to version 5.12, the verification of the second fact
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
nvd
CVE-2025-61587P4MEDIUMCVSS 6.1fixed in 5.13.32025-10-01
CVE-2025-61587 [MEDIUM] CWE-601 CVE-2025-61587: Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via t
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to
nvd
CVE-2025-49134P4MEDIUMCVSS 5.3fixed in 5.122025-06-16
CVE-2025-49134 [MEDIUM] CWE-359 CVE-2025-49134: Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications include
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
nvd
CVE-2026-33440P4MEDIUMCVSS 5.0fixed in 5.172026-04-15
CVE-2026-33440 [MEDIUM] CWE-918 CVE-2026-33440: Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setti
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.
nvd
CVE-2022-24710P4MEDIUMCVSS 5.4fixed in 4.112022-02-25
CVE-2022-24710 [MEDIUM] CWE-79 CVE-2022-24710: Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do n
Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The issues were fixed in the 4.11 release. Users unable to upgrade are advised
nvd
CVE-2026-45106P4MEDIUMCVSS 4.6fixed in 2026.52026-06-10
CVE-2026-45106 [MEDIUM] CWE-79 CVE-2026-45106: Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview ren
Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search. This issue has been patched in version 202
nvd
CVE-2026-61790P4MEDIUMCVSS 4.4fixed in 2026.72026-08-26
CVE-2026-61790 [MEDIUM] CWE-284 CVE-2026-61790: Weblate is a web-based continuous localization platform used to manage software translations. In ver
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, a team can require its members to configure two-factor authentication before receiving the team's permissions, but this requirement is not enforced for site-wide global permissions. As a result, a user who belongs to a team that
nvd
CVE-2026-27457P4MEDIUMCVSS 4.3fixed in 5.16.12026-02-26
CVE-2026-27457 [MEDIUM] CWE-200 CVE-2026-27457: Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`w
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`, line 2831) uses `queryset = Addon.objects.all()` without overriding `get_queryset()` to scope results by user permissions. This allows any authenticated user (or anonymous users if `REQUIRE_LOGIN` is not set) to list and retrieve
nvd
CVE-2026-44263P4MEDIUMCVSS 4.3fixed in 5.17.12026-05-07
CVE-2026-44263 [MEDIUM] CWE-203 CVE-2026-44263: Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and compo
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1.
nvd
CVE-2026-33214P4MEDIUMCVSS 4.3fixed in 5.172026-04-15
CVE-2026-33214 [MEDIUM] CWE-862 CVE-2026-33214: Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API expo
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't enforce proper access control. This issue has been fixed in version 5.17. If users are unable to update immediately, they can work around this issue by blocking access to /api/memory/ in the HTTP server,
nvd
CVE-2026-55227P4MEDIUMCVSS 4.3fixed in 2026.72026-08-26
CVE-2026-55227 [MEDIUM] CWE-203 CVE-2026-55227: Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up obj
Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather than restricting the lookup to projects the user can access, so they return HTTP 403 (Forbidden) instead of 404 (Not Found) when a user requests an object they are not authorized to see. This difference lets una
nvd
CVE-2026-62249P4MEDIUMCVSS 4.3fixed in 2026.72026-08-26
CVE-2026-62249 [MEDIUM] CWE-200 CVE-2026-62249: Weblate is a web-based continuous localization platform used to manage software translations. In ver
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, an authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those components directly. The nested e
nvd
CVE-2025-67715P4MEDIUMCVSS 4.3fixed in 5.152025-12-16
CVE-2025-67715 [MEDIUM] CWE-284 CVE-2025-67715: Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve use
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.
nvd
CVE-2026-44264P4MEDIUMCVSS 4.3fixed in 5.17.12026-05-07
CVE-2026-44264 [MEDIUM] CWE-80 CVE-2026-44264: Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in use
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1.
nvd
CVE-2026-39845P4MEDIUMCVSS 4.1fixed in 5.172026-04-15
CVE-2026-39845 [MEDIUM] CWE-918 CVE-2026-39845: Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not util
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF protections. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable the webhook add-on as a workaround.
nvd
CVE-2026-77508P4LOWCVSS 3.5fixed in 2026.82026-08-26
CVE-2026-77508 [LOW] CWE-302 CVE-2026-77508: Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the acco
Weblate is a web based localization tool. Prior to 2026.8, an authenticated user can change the account's primary email through PUT or PATCH requests to /api/users/{username}/ without verifying the new address, allowing a later team invitation for that address to be accepted without access to the intended recipient's mailbox. This issue is fixed in ver
nvd
CVE-2026-77573P4LOWCVSS 3.5fixed in 2026.82026-08-26
CVE-2026-77573 [LOW] CWE-367 CVE-2026-77573: Weblate is a web-based continuous localization platform used to manage software translations. In ver
Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.8, a user permitted to manage component repository URLs can perform server-side request forgery against internal services through DNS rebinding during VCS operations. Weblate validates the hostname's first DNS resolution, but the exte
nvd