VulnSea

weblate has 23 CVEs on record between 2024 and 2026. Disclosures have slowed: 3 in the last 90 days after 10 in the 90 before. The busiest recent month was April 2026 with 7. The median CVSS is 5.0 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
5.0
Publish → KEV
Last 90 days
3 prev 10

Products

  • weblate 23
23
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

weblate vulnerabilities

CVEs affecting weblate, newest first. Open any entry for full detail, references, and exploit status.

23 CVEsRSS

CVE-2026-55227Medium· 4.3
3w ago

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups

Sunlitweblate · weblateEPSS 0.19%via OSV
CVE-2026-55228High· 8.1
3w ago

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project

Twilightweblate · weblateEPSS 0.26%via OSV
CVE-2026-50127Medium· 5.9
2mo ago

Weblate SSRF: outbound URL guard misses some private ranges

Weblate SSRF: outbound URL guard misses some private ranges

Sunlitweblate · weblateEPSS 0.31%via GHSA
CVE-2026-45106Medium· 4.6
4mo ago

Weblate: Stored HTML injection in editor search preview

Weblate: Stored HTML injection in editor search preview

Sunlitweblate · weblateEPSS 0.21%via OSV
CVE-2026-44263Medium· 4.3
4mo ago

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

Weblate Vulnerable to Private Translation Enumeration via Screenshot API

Sunlitweblate · weblateEPSS 0.29%via OSV
CVE-2026-44264Medium· 4.3
4mo ago

Weblate vulnerable to XSS via crafted Markdown

Weblate vulnerable to XSS via crafted Markdown

Sunlitweblate · weblateEPSS 0.27%via OSV
CVE-2026-41654Medium
4mo ago

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Sunlitweblate · weblateEPSS 0.37%via OSV
CVE-2026-41519Medium· 4.2
4mo ago

Weblate Doesn't Invalidate API Token on Password Change

Weblate Doesn't Invalidate API Token on Password Change

Sunlitweblate · weblateEPSS 0.27%via OSV
CVE-2026-34244Medium· 5.0
5mo ago

Weblate: SSRF via Project-Level Machinery Configuration

Weblate: SSRF via Project-Level Machinery Configuration

Sunlitweblate · weblateEPSS 0.25%via OSV
CVE-2026-33212Low· 3.1
5mo ago

Weblate: Improper access control for pending tasks in API

Weblate: Improper access control for pending tasks in API

Sunlitweblate · weblateEPSS 0.22%via OSV
CVE-2026-34242High· 7.7
5mo ago

Weblate: Arbitrary File Read via Symlink

Weblate: Arbitrary File Read via Symlink

Twilightweblate · weblateEPSS 0.46%via OSV
CVE-2026-40256Medium· 5.0
5mo ago

Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2026-33440Medium· 5.0
5mo ago

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Sunlitweblate · weblateEPSS 0.24%via OSV
CVE-2026-27457Medium· 4.3
6mo ago

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

Sunlitweblate · weblateEPSS 0.30%via OSV
CVE-2026-24126Medium· 6.6PoC
7mo ago

Weblate has an argument injection in management console

Weblate has an argument injection in management console

Twilightweblate · weblateEPSS 0.46%via OSV
CVE-2026-21889Low
8mo ago

Weblate leaks information via screenshots

Weblate leaks information via screenshots

Sunlitweblate · weblateEPSS 0.38%via OSV
CVE-2025-68279High· 7.7
9mo ago

Weblate has an arbitrary file read via symbolic links

Weblate has an arbitrary file read via symbolic links

Twilightweblate · weblateEPSS 0.41%via OSV
CVE-2025-64725Low
9mo ago

Weblate has improper validation upon invitation acceptance

Weblate has improper validation upon invitation acceptance

Sunlitweblate · weblateEPSS 0.35%via OSV
CVE-2025-61587Medium· 6.1
11mo ago

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website…

Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL…

Sunlitweblate · weblateEPSS 0.39%via OSV
CVE-2025-58352Low
1y ago

Weblate has a long session expiry when verifying second factor

Weblate has a long session expiry when verifying second factor

Sunlitweblate · weblateEPSS 0.28%via OSV
CVE-2025-47951Medium· 4.9
1y ago

Weblate lacks rate limiting when verifying second factor

Weblate lacks rate limiting when verifying second factor

Sunlitweblate · weblateEPSS 0.27%via OSV
CVE-2025-49134Medium· 5.3
1y ago

Weblate exposes personal IP address via e-mail

Weblate exposes personal IP address via e-mail

Sunlitweblate · weblateEPSS 0.32%via OSV
CVE-2024-39303Medium· 4.4
2y ago

Weblate vulnerable to improper sanitization of project backups

Weblate vulnerable to improper sanitization of project backups

Sunlitweblate · weblateEPSS 0.32%via OSV
weblate vulnerabilities (CVEs) · VulnSea