weblate has 23 CVEs on record between 2024 and 2026. Disclosures have slowed: 3 in the last 90 days after 10 in the 90 before. The busiest recent month was April 2026 with 7. The median CVSS is 5.0 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.0
- Publish → KEV
- —
- Last 90 days
- 3 prev 10
Worst active — by depth score
CVE-2026-24126Medium· 6.6Weblate has an argument injection in management console48CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project45CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink42CVE-2025-68279High· 7.7Weblate has an arbitrary file read via symbolic links42CVE-2025-61587Medium· 6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…34
weblate vulnerabilities
CVEs affecting weblate, newest first. Open any entry for full detail, references, and exploit status.
23 CVEsRSS
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-50127Medium· 5.9Weblate SSRF: outbound URL guard misses some private ranges
Weblate SSRF: outbound URL guard misses some private ranges
CVE-2026-45106Medium· 4.6Weblate: Stored HTML injection in editor search preview
Weblate: Stored HTML injection in editor search preview
CVE-2026-44263Medium· 4.3Weblate Vulnerable to Private Translation Enumeration via Screenshot API
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-44264Medium· 4.3Weblate vulnerable to XSS via crafted Markdown
Weblate vulnerable to XSS via crafted Markdown
CVE-2026-41654MediumWeblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-41519Medium· 4.2Weblate Doesn't Invalidate API Token on Password Change
Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API
Weblate: Improper access control for pending tasks in API
CVE-2026-34242High· 7.7Weblate: Arbitrary File Read via Symlink
Weblate: Arbitrary File Read via Symlink
CVE-2026-40256Medium· 5.0Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVE-2026-33440Medium· 5.0Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-24126Medium· 6.6PoCWeblate has an argument injection in management console
Weblate has an argument injection in management console
CVE-2026-21889LowWeblate leaks information via screenshots
Weblate leaks information via screenshots
CVE-2025-68279High· 7.7Weblate has an arbitrary file read via symbolic links
Weblate has an arbitrary file read via symbolic links
CVE-2025-64725LowWeblate has improper validation upon invitation acceptance
Weblate has improper validation upon invitation acceptance
CVE-2025-61587Medium· 6.1Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…
CVE-2025-58352LowWeblate has a long session expiry when verifying second factor
Weblate has a long session expiry when verifying second factor
CVE-2025-47951Medium· 4.9Weblate lacks rate limiting when verifying second factor
Weblate lacks rate limiting when verifying second factor
CVE-2025-49134Medium· 5.3Weblate exposes personal IP address via e-mail
Weblate exposes personal IP address via e-mail
CVE-2024-39303Medium· 4.4Weblate vulnerable to improper sanitization of project backups
Weblate vulnerable to improper sanitization of project backups