Vulnerability index

Browse CVEs

27 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.1 CVE-2026-41654 Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS … Weblate 5.17.1+ Fix from $1,9502026-05-07 MEDIUM 5.4 CVE-2026-41519 Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via… Weblate 5.17.1+ Fix from $1,6002026-05-07 MEDIUM 5.0 CVE-2026-40256 Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string prefix checks on resolved absolu… Weblate 5.17+ Fix from $1,6002026-04-15 HIGH 8.8 CVE-2026-34393 Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This is… Weblate 5.17+ Fix from $1,9502026-04-15 HIGH 8.0 CVE-2026-33435 Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which cou… Weblate 5.17+ Fix from $1,9502026-04-15 HIGH 7.7 CVE-2026-34242 Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following … Weblate 5.17+ Fix from $1,9502026-04-15 MEDIUM 6.8 CVE-2026-33220 Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't pe… Weblate 5.17+ Fix from $1,6002026-04-15 MEDIUM 5.0 CVE-2026-33440 Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and … Weblate 5.17+ Fix from $1,6002026-04-15 MEDIUM 5.0 CVE-2026-34244 Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administrat… Weblate 5.17+ Fix from $1,6002026-04-15 CRITICAL 9.1 CVE-2026-24126 Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key… Weblate 5.16+ Fix from $2,3002026-02-19 HIGH 8.0 CVE-2026-23535 wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location w… Wlc 1.17.2+ Fix from $1,9502026-01-16 HIGH 7.5 CVE-2026-21889 Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access contro… Weblate 5.15.2+ Fix from $1,9502026-01-14 MEDIUM 5.5 CVE-2026-22250 wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vul… Wlc 1.17.0+ Fix from $1,6002026-01-12 MEDIUM 5.5 CVE-2026-22251 wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practi… Wlc 1.17.0+ Fix from $1,6002026-01-12 CRITICAL 9.1 CVE-2025-68398 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of i… Weblate 5.15.1+ Fix from $2,3002025-12-18 MEDIUM 6.5 CVE-2025-68279 Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to read arbitrary files from the server file system using craf… Weblate 5.15.1+ Fix from $1,6002025-12-18 MEDIUM 5.3 CVE-2025-67492 Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafte… Weblate 5.15+ Fix from $1,6002025-12-16 MEDIUM 5.0 CVE-2025-66407 Weblate is a web based localization tool. The Create Component functionality in Weblate allows authorized users to add new translation components by … Weblate 5.15+ Fix from $1,6002025-12-16 CRITICAL 9.8 CVE-2025-64725 Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15… Weblate 5.15+ Fix from $2,3002025-12-15 MEDIUM 6.1 CVE-2025-61587 Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblat… Weblate 5.13.3+ Fix from $1,6002025-10-01 MEDIUM 6.5 CVE-2025-58352 Weblate is a web based localization tool. Versions lower than 5.13.1 contain a vulnerability that causes long session expiry during the second facto… Weblate 5.13.1+ Fix from $1,6002025-09-05 MEDIUM 5.3 CVE-2025-49134 Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This co… Weblate 5.12+ Fix from $1,6002025-06-16 HIGH 7.5 CVE-2025-32021 Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repo… Weblate 5.11+ Fix from $1,9502025-04-15 MEDIUM 5.4 CVE-2024-39303 Weblate is a web based localization tool. Prior to version 5.6.2, Weblate didn't correctly validate filenames when restoring project backup. It may b… Weblate 5.6.2+ Fix from $1,6002024-07-01 HIGH 8.8 CVE-2022-23915 The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial reposit… Weblate 4.11.1+ Fix from $1,9502022-03-04 MEDIUM 5.4 CVE-2022-24710 Weblate is a copyleft software web-based continuous localization system. Versions prior to 4.11 do not properly neutralize user input used in user na… Weblate 4.11+ Fix from $1,6002022-02-25 MEDIUM 5.3 CVE-2017-5537 The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an accou… Weblate after 2.10 Fix from $1,6002017-03-15