Cross-Site Scripting in Weblate Localization Tool Affects User Security
CVE-2026-45106
4.6MEDIUM
What is CVE-2026-45106?
Weblate, a web-based localization tool, has a vulnerability that allows cross-site scripting due to improper HTML rendering in its live search preview feature. Before version 2026.5, the tool failed to escape HTML and CSS, enabling contributors to inject malicious code into the unit source and context fields. This code executes in the context of the authenticated editor for any user performing a matching search, potentially compromising user security. The issue has since been patched in the release of version 2026.5.
Affected Version(s)
weblate < 2026.5
