vciy

CVEs we hold for Weblateorg

Records whose assigning authority named Weblateorg as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-77573Weblate: DNS rebinding in VCS operations allows server-side request forgeryWeblateOrg weblate
CVE-2026-77508Weblate: Unverified REST API email changesWeblateOrg weblate
CVE-2026-77507Weblate: Object-scoped RSS feeds disclose private change history to unauthorized usersWeblateOrg weblate
CVE-2026-62326Weblate Has Uncontrolled Resource Consumption viaWeblateOrg weblate
CVE-2026-62249Weblate: Restricted-component change history leaked to non-member project users through the nested `GET…WeblateOrg weblate
CVE-2026-61792Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download…WeblateOrg weblate
CVE-2026-61790Weblate: Team-enforced 2FA is bypassed for global permissionsWeblateOrg weblate
CVE-2026-55228Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private…WeblateOrg weblate
CVE-2026-55227Observable object existence disclosure in private Weblate projects via globally scoped object lookupsWeblateOrg weblate
CVE-2026-50127Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)WeblateOrg weblate
CVE-2026-45106Weblate: Stored HTML injection in editor search previewWeblateOrg weblate
CVE-2026-44264Weblate is vulnerable to XSS via crafted MarkdownWeblateOrg weblate
CVE-2026-44263Weblate: Private Translation Enumeration via Screenshot APIWeblateOrg weblate
CVE-2026-42150wlc: print_html outputs API data without HTML escaping, enabling stored XSSWeblateOrg wlc
CVE-2026-41654Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlWeblateOrg weblate
CVE-2026-41519Weblate's API Token Not Invalidated on Password ChangeWeblateOrg weblate
CVE-2026-40256Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionWeblateOrg weblate
CVE-2026-39845Weblate: SSRF via the webhook add-on using unprotected fetch_url()WeblateOrg weblate
CVE-2026-34393Weblate: Privilege escalation in the user API endpointWeblateOrg weblate
CVE-2026-34244Weblate: SSRF via Project-Level Machinery ConfigurationWeblateOrg weblate
CVE-2026-34242Weblate: Arbitrary File Read via SymlinkWeblateOrg weblate
CVE-2026-33440Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsWeblateOrg weblate
CVE-2026-33435Weblate: Remote code execution during backup restorationWeblateOrg weblate
CVE-2026-33220Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryWeblateOrg weblate
CVE-2026-33214Weblate has improper access control for the translation memory APIWeblateOrg weblate
CVE-2026-33212Weblate: Improper access control for pending tasks in APIWeblateOrg weblate
CVE-2026-27457Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsWeblateOrg weblate
CVE-2026-24126Weblate has an argument injection in management consoleWeblateOrg weblate
CVE-2026-23535wlc Path traversal: Unsanitized API slugs in download commandWeblateOrg wlc
CVE-2026-22251wlc may leak API keys due to an insecure API key configurationWeblateOrg wlc
CVE-2026-22250wlc can skip SSL verificationWeblateOrg wlc
CVE-2026-21889Weblate leaks information via screenshotsWeblateOrg weblate
CVE-2025-68398Weblate has git config file overwrite vulnerability that leads to remote code executionWeblateOrg weblate
CVE-2025-68279Weblate has an arbitrary file read via symbolic linksWeblateOrg weblate
CVE-2025-67715Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)WeblateOrg weblate
CVE-2025-67492Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumerationWeblateOrg weblate
CVE-2025-66407Weblate has Server-Side Request Forgery vulnerabilityWeblateOrg weblate
CVE-2025-64725Weblate has improper validation upon invitation acceptanceWeblateOrg weblate
CVE-2025-64326Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit logWeblateOrg weblate
CVE-2025-61587Weblate integration with Anubis can lead to Open Redirect via redir parameterWeblateOrg weblate
CVE-2025-58352Weblate has long session expiry times during second factor verificationWeblateOrg weblate
CVE-2025-49134Weblate exposes personal IP address via e-mailWeblateOrg weblate
CVE-2025-47951Weblate lacks rate limiting when verifying second factorWeblateOrg weblate
CVE-2025-32021Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintextWeblateOrg weblate
CVE-2024-39303Weblate vulnerabler to improper sanitization of project backupsWeblateOrg weblate
CVE-2022-24710Cross-site Scripting in WeblateWeblateOrg weblate

46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.