weblateorg Weblate Vulnerabilities
Weblateorg Weblate vulnerabilities.
Vulnerability Published:
ποΈ Published
- Anytime
Sort By:
ποΈ Published Date
- Descending
Weblate: DNS rebinding in VCS operations allows server-side request forgery
CVE-2026-77573WeblateorgWeblate3.5LOWWeblate: Object-scoped RSS feeds disclose private change history to unauthorized users
CVE-2026-77507WeblateorgWeblate5.3MEDIUMWeblate Has Uncontrolled Resource Consumption via
CVE-2026-62326WeblateorgWeblate6.5MEDIUMWeblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpoint
CVE-2026-62249WeblateorgWeblate4.3MEDIUMWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)
CVE-2026-61792WeblateorgWeblate7.7HIGHWeblate: Team-enforced 2FA is bypassed for global permissions
CVE-2026-61790WeblateorgWeblate4.4MEDIUMWeblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-55228WeblateorgWeblate8.1HIGHObservable object existence disclosure in private Weblate projects via globally scoped object lookups
CVE-2026-55227WeblateorgWeblate4.3MEDIUMAccount Email Modification Vulnerability in Weblate Localization Tool
CVE-2026-77508WeblateorgWeblate3.5LOWCross-Site Scripting in Weblate Localization Tool Affects User Security
CVE-2026-45106WeblateorgWeblate4.6MEDIUMWeblate Localization Tool Vulnerability in Version 5.15 to Prior to 2026.6
CVE-2026-50127WeblateorgWeblate5.9MEDIUMWeblate Localization Tool Vulnerability in User-Provided Content
CVE-2026-44264WeblateorgWeblate4.3MEDIUMWeblate Localization Tool Vulnerability in Affected Versions
CVE-2026-44263WeblateorgWeblate4.3MEDIUMWeblate Authentication Vulnerability in Web-Based Localization Tool
CVE-2026-41519WeblateorgWeblate4.2MEDIUMVulnerability in Weblate Localization Tool Allows Unchecked Repo URLs from Project Backups
CVE-2026-41654WeblateorgWeblate5.3MEDIUMPath Traversal Vulnerability in Weblate Localization Tool
CVE-2026-40256WeblateorgWeblate5MEDIUMSSRF Vulnerability in Weblate Localization Tool by Weblate
CVE-2026-39845WeblateorgWeblate4.1MEDIUMUser Patching API Exposure in Weblate Localization Tool
CVE-2026-34393WeblateorgWeblate8.8HIGHServer-Side Request Forgery Vulnerability in Weblate Localization Tool
CVE-2026-34244WeblateorgWeblate5MEDIUMSymlink Vulnerability in Weblate Localization Tool
CVE-2026-34242WeblateorgWeblate7.7HIGHWeblate Localization Tool Vulnerability in Prior Versions
CVE-2026-33440WeblateorgWeblate5MEDIUMWeblate Localization Tool Vulnerability Exposes Project Backup Risks
CVE-2026-33435WeblateorgWeblate8.1HIGHAccess Control Flaw in Weblate Translation Memory API Exposes Unintended Endpoints
CVE-2026-33220WeblateorgWeblate6.8MEDIUMAccess Control Issues in Weblate Localization Tool by Weblate
CVE-2026-33214WeblateorgWeblate4.3MEDIUMAccess Control Weakness in Weblate Localization Tool
CVE-2026-33212WeblateorgWeblate3.1LOW