CVE-2026-44264Medium· 4.3▾ SunlitWeblate vulnerable to XSS via crafted Markdown
▾ Sunlit zone — Low / medium · no exploitation signal
impact 23.7 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 13.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.3%
The Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes.
Even though the attacker might be able to inject code into the HTML, the Weblate's strict CSP should mitigate the risks.
Michal Čihař has identified and fixed this vulnerability.
weblate < 5.17.1Upgrade to a patched release:
weblate 5.17.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-41654MediumWeblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-41519Medium· 4.2Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration