VYPR

Weblate

by Weblateorg

pypi: weblate

Source repositories

CVEs (35)

  • CVE-2025-64725CriDec 15, 2025
    risk 0.57cvss 9.8epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

  • CVE-2025-68398CriDec 18, 2025
    risk 0.52cvss 9.1epss 0.01

    Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fixes the issue.

  • CVE-2026-34393HigApr 15, 2026
    risk 0.50cvss 8.8epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5.17.

  • CVE-2026-41654HigMay 7, 2026
    risk 0.46cvss 8.1epss 0.00

    Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json…

  • CVE-2026-33435HigApr 15, 2026
    risk 0.45cvss 8.0epss 0.01

    Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code execution under certain circumstances. This issue has been fixed in version 5.17. If developers are unable…

  • CVE-2026-34242HigApr 15, 2026
    risk 0.43cvss 7.7epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository. This issue has been fixed in version 5.17.

  • CVE-2025-68279HigDec 18, 2025
    risk 0.43cvss 7.7epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. Version 5.15.1 fixes the issue.

  • CVE-2026-21889HigJan 14, 2026
    risk 0.42cvss 7.5epss 0.00

    Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. This vulnerability is fixed in…

  • CVE-2022-23915HigMar 4, 2022
    risk 0.40cvss 7.2epss 0.04

    The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.

  • CVE-2026-33220MedApr 15, 2026
    risk 0.37cvss 6.8epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can…

  • CVE-2026-24126MedFeb 19, 2026
    risk 0.36cvss 6.6epss 0.00

    Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to `ssh-add`. Version 5.16.0 fixes the issue. As a workaround, properly limit access…

  • CVE-2025-58352MedSep 5, 2025
    risk 0.35cvss 6.5epss 0.00

    Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second factor verification. The long session expiry could be used to circumvent rate limiting of the second factor. This issue is fixed in…

  • CVE-2026-50127MedJun 10, 2026
    risk 0.31cvss 5.9epss 0.00

    Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, or some semi-private IPv4 ranges, which allowed some addresses to bypass private…

  • CVE-2022-24710MedFeb 25, 2022
    risk 0.28cvss 5.4epss 0.01

    Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user name and language fields. Due to this improper neutralization it is possible to perform cross-site scripting via these fields. The…

  • CVE-2017-5537MedMar 15, 2017
    risk 0.28cvss 5.3epss 0.02

    The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.

  • CVE-2025-67492MedDec 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this…

  • CVE-2025-49134MedJun 16, 2025
    risk 0.27cvss 5.3epss 0.00

    Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.

  • CVE-2026-40256MedApr 15, 2026
    risk 0.26cvss 5.0epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and…

  • CVE-2026-34244MedApr 15, 2026
    risk 0.26cvss 5.0epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration…

  • CVE-2026-33440MedApr 15, 2026
    risk 0.26cvss 5.0epss 0.00

    Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. This issue has been fixed in version 5.17.

Page 1 of 2