Cross-Site Scripting in Weblate Localization Tool Affects User Security
CVE-2026-45106

4.6MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
10 June 2026

What is CVE-2026-45106?

Weblate, a web-based localization tool, has a vulnerability that allows cross-site scripting due to improper HTML rendering in its live search preview feature. Before version 2026.5, the tool failed to escape HTML and CSS, enabling contributors to inject malicious code into the unit source and context fields. This code executes in the context of the authenticated editor for any user performing a matching search, potentially compromising user security. The issue has since been patched in the release of version 2026.5.

Affected Version(s)

weblate < 2026.5

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.