CVE-2026-42150Medium· 5.1▾ Sunlitwlc: print_html outputs API data without HTML escaping
▾ Sunlit zone — Low / medium · no exploitation signal
impact 28.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
The HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser.
The only vulnerable code path is HTML output which is opt-in.
Weblate thanks @fg0x0 for reporting this on GitHub.
wlc < 2.0.0Upgrade to a patched release:
wlc 2.0.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-23535High· 8.0Weblate wlc path traversal vulnerability: Unsanitized API slugs in download command
CVE-2026-22251Medium· 5.3Weblate wlc has insecure API key configuration
CVE-2026-22250Low· 2.5Weblate command-line client susceptible to SSL verification skip