weblate vulnerabilities
CVEs whose affected-version data names the weblate package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
23 CVEsRSS
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-50127Medium· 5.9Weblate SSRF: outbound URL guard misses some private ranges
Weblate SSRF: outbound URL guard misses some private ranges
CVE-2026-45106Medium· 4.6Weblate: Stored HTML injection in editor search preview
Weblate: Stored HTML injection in editor search preview
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-44264Medium· 4.3Weblate vulnerable to XSS via crafted Markdown
Weblate vulnerable to XSS via crafted Markdown
CVE-2026-41654MediumWeblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-41519Medium· 4.2Weblate Doesn't Invalidate API Token on Password Change
Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API
Weblate: Improper access control for pending tasks in API
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
Weblate: Arbitrary File Read via Symlink
CVE-2026-40256Medium· 5.0Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVE-2026-33440Medium· 5.0Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-24126Medium· 6.6PoCWeblate has an argument injection in management console
Weblate has an argument injection in management console
CVE-2026-21889LowWeblate leaks information via screenshots
Weblate leaks information via screenshots
CVE-2025-68279High· 7.7Weblate has an arbitrary file read via symbolic links
Weblate has an arbitrary file read via symbolic links
CVE-2025-64725LowWeblate has improper validation upon invitation acceptance
Weblate has improper validation upon invitation acceptance
CVE-2025-61587Medium· 6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…
CVE-2025-58352LowWeblate has a long session expiry when verifying second factor
Weblate has a long session expiry when verifying second factor
CVE-2025-47951Medium· 4.9Weblate lacks rate limiting when verifying second factor
Weblate lacks rate limiting when verifying second factor
CVE-2025-49134Medium· 5.3Weblate exposes personal IP address via e-mail
Weblate exposes personal IP address via e-mail
CVE-2024-39303Medium· 4.4Weblate vulnerable to improper sanitization of project backups
Weblate vulnerable to improper sanitization of project backups