CVEs we hold for Weblateorg
Records whose assigning authority named Weblateorg as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-77573Weblate: DNS rebinding in VCS operations allows server-side request forgeryWeblateOrg weblate
CVE-2026-77507Weblate: Object-scoped RSS feeds disclose private change history to unauthorized usersWeblateOrg weblate
CVE-2026-62249Weblate: Restricted-component change history leaked to non-member project users through the nested `GET…WeblateOrg weblate
CVE-2026-61792Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download…WeblateOrg weblate
CVE-2026-55228Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private…WeblateOrg weblate
CVE-2026-55227Observable object existence disclosure in private Weblate projects via globally scoped object lookupsWeblateOrg weblate
CVE-2026-50127Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)WeblateOrg weblate
CVE-2026-42150wlc: print_html outputs API data without HTML escaping, enabling stored XSSWeblateOrg wlc
CVE-2026-41654Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlWeblateOrg weblate
CVE-2026-40256Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionWeblateOrg weblate
CVE-2026-33440Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsWeblateOrg weblate
CVE-2026-33220Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryWeblateOrg weblate
CVE-2026-27457Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsWeblateOrg weblate
CVE-2025-68398Weblate has git config file overwrite vulnerability that leads to remote code executionWeblateOrg weblate
CVE-2025-67715Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)WeblateOrg weblate
CVE-2025-67492Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumerationWeblateOrg weblate
CVE-2025-64326Weblate leaks the IP of project members inviting users to assume reviewer roles in Audit logWeblateOrg weblate
CVE-2025-61587Weblate integration with Anubis can lead to Open Redirect via redir parameterWeblateOrg weblate
CVE-2025-58352Weblate has long session expiry times during second factor verificationWeblateOrg weblate
CVE-2025-32021Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintextWeblateOrg weblate
46 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.