Weblateorg Weblate vulnerabilities
42 known vulnerabilities affecting weblateorg/weblate.
Total CVEs
42
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH8MEDIUM27LOW4
Vulnerabilities
Page 3 of 3
CVE-2026-33212P4LOWCVSS 3.1fixed in 5.172026-04-15
CVE-2026-33212 [LOW] CWE-284 CVE-2026-33212: Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify use
Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. The attacker needs to brute-force the random UUID of the task, so exploiting this is unlikely with the default API rate limits. Th
nvd
CVE-2025-64326P4LOWCVSS 3.5fixed in 5.14.12025-11-06
CVE-2025-64326 [LOW] CWE-212 CVE-2025-64326: Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.
nvd
← Previous3 / 3