weblate kayıtları
weblate üreticisine ait 37 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 1
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-284 Improper Access Control3
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-613 Insufficient Session Expiration2
- CWE-20 Improper Input Validation2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWEBug bounty kapsamı
Ürünün üreticisi herkese açık bir programda görünüyor. Eşleşme ad üzerinden yapıldı; kapsam metnini programda doğrulayın.
Tüm kayıtlar
37 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
36İzleyin | CVE-2022-23915İstismar yok | Remote Code Execution (RCE)weblate · weblate · CWE-88 | Yüksek8,8 | — | %3,9 | 4 Mar 2022 |
36İzleyin | CVE-2025-68398İstismar yok | Weblate has git config file overwrite vulnerability that leads to remote code executionweblate · weblate · CWE-20 | Kritik9,1 | — | %0,8 | 18 Ara 2025 |
36İzleyin | CVE-2026-24126Kavram kanıtı | Weblate has an argument injection in management consoleweblate · weblate · CWE-88 | Kritik9,1 | — | %0,5 | 18 Şub 2026 |
35İzleyin | CVE-2026-34393İstismar yok | Weblate: Privilege escalation in the user API endpointweblate · weblate · CWE-269 | Yüksek8,8 | — | %0,5 | 15 Nis 2026 |
32İzleyin | CVE-2026-33435İstismar yok | Weblate: Remote code execution during backup restorationweblate · weblate · CWE-23 | Yüksek8,0 | — | %0,9 | 15 Nis 2026 |
32İzleyin | CVE-2026-23535İstismar yok | wlc Path traversal: Unsanitized API slugs in download commandweblate · wlc · CWE-22 | Yüksek8,0 | — | %0,4 | 16 Oca 2026 |
30İzleyin | CVE-2026-34242İstismar yok | Weblate: Arbitrary File Read via Symlinkweblate · weblate · CWE-22 | Yüksek7,7 | — | %0,5 | 15 Nis 2026 |
30İzleyin | CVE-2025-32021İstismar yok | Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintextweblate · weblate · CWE-598 | Yüksek7,5 | — | %0,4 | 15 Nis 2025 |
27İzleyin | CVE-2026-33220İstismar yok | Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryweblate · weblate · CWE-22 | Orta6,8 | — | %0,4 | 15 Nis 2026 |
26İzleyin | CVE-2025-68279İstismar yok | Weblate has an arbitrary file read via symbolic linksweblate · weblate · CWE-22 | Orta6,5 | — | %0,4 | 18 Ara 2025 |
22İzleyin | CVE-2017-5537İstismar yok | The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated withweblate · weblate · CWE-200 | Orta5,3 | — | %2,3 | 15 Mar 2017 |
22İzleyin | CVE-2026-22251İstismar yok | wlc may leak API keys due to an insecure API key configurationweblate · wlc · CWE-200 | Orta5,5 | — | %0,2 | 12 Oca 2026 |
22İzleyin | CVE-2026-22250İstismar yok | wlc can skip SSL verificationweblate · wlc · CWE-295 | Orta5,5 | — | %0,2 | 12 Oca 2026 |
21İzleyin | CVE-2022-24710İstismar yok | Cross-site Scripting in Weblateweblate · weblate · CWE-79 | Orta5,4 | — | %0,8 | 25 Şub 2022 |
21İzleyin | CVE-2026-41654İstismar yok | Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlweblate · weblate · CWE-20 | Orta5,3 | — | %0,5 | 7 May 2026 |
21İzleyin | CVE-2026-41519İstismar yok | Weblate's API Token Not Invalidated on Password Changeweblate · weblate · CWE-613 | Orta5,4 | — | %0,4 | 7 May 2026 |
21İzleyin | CVE-2024-39303İstismar yok | Weblate vulnerabler to improper sanitization of project backupsweblate · weblate · CWE-73 | Orta5,4 | — | %0,3 | 1 Tem 2024 |
21İzleyin | CVE-2025-67492İstismar yok | Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumerationweblate · weblate · CWE-1286 | Orta5,3 | — | %0,3 | 15 Ara 2025 |
20İzleyin | CVE-2026-40256İstismar yok | Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collisionweblate · weblate · CWE-22 | Orta5,0 | — | %0,4 | 15 Nis 2026 |
20İzleyin | CVE-2026-34244İstismar yok | Weblate: SSRF via Project-Level Machinery Configurationweblate · weblate · CWE-200 | Orta5,0 | — | %0,3 | 15 Nis 2026 |
20İzleyin | CVE-2026-33440İstismar yok | Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsweblate · weblate · CWE-918 | Orta5,0 | — | %0,3 | 15 Nis 2026 |
20İzleyin | CVE-2025-66407İstismar yok | Weblate has Server-Side Request Forgery vulnerabilityweblate · weblate · CWE-352 | Orta5,0 | — | %0,2 | 15 Ara 2025 |
19İzleyin | CVE-2026-42150İstismar yok | wlc: print_html outputs API data without HTML escaping, enabling stored XSSweblate · wlc · CWE-79 | Orta4,8 | — | %0,3 | 8 May 2026 |
19İzleyin | CVE-2025-47951İstismar yok | Weblate lacks rate limiting when verifying second factorweblate · weblate · CWE-307 | Orta4,9 | — | %0,3 | 16 Haz 2025 |
17İzleyin | CVE-2026-27457İstismar yok | Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsweblate · weblate · CWE-200 | Orta4,3 | — | %0,4 | 26 Şub 2026 |
- CVE-2022-2391536İzleyin
Remote Code Execution (RCE)
YüksekCVSS 8,8İstismar yokEPSS %4weblate · weblate4 Mar 2022
- CVE-2025-6839836İzleyin
Weblate has git config file overwrite vulnerability that leads to remote code execution
KritikCVSS 9,1İstismar yokEPSS %1weblate · weblate18 Ara 2025
- CVE-2026-2412636İzleyin
Weblate has an argument injection in management console
KritikCVSS 9,1Kavram kanıtıEPSS %0weblate · weblate18 Şub 2026
- CVE-2026-3439335İzleyin
Weblate: Privilege escalation in the user API endpoint
YüksekCVSS 8,8İstismar yokEPSS %1weblate · weblate15 Nis 2026
- CVE-2026-3343532İzleyin
Weblate: Remote code execution during backup restoration
YüksekCVSS 8,0İstismar yokEPSS %1weblate · weblate15 Nis 2026
- CVE-2026-2353532İzleyin
wlc Path traversal: Unsanitized API slugs in download command
YüksekCVSS 8,0İstismar yokEPSS %0weblate · wlc16 Oca 2026
- CVE-2026-3424230İzleyin
Weblate: Arbitrary File Read via Symlink
YüksekCVSS 7,7İstismar yokEPSS %1weblate · weblate15 Nis 2026
- CVE-2025-3202130İzleyin
Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
YüksekCVSS 7,5İstismar yokEPSS %0weblate · weblate15 Nis 2025
- CVE-2026-3322027İzleyin
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
OrtaCVSS 6,8İstismar yokEPSS %0weblate · weblate15 Nis 2026
- CVE-2025-6827926İzleyin
Weblate has an arbitrary file read via symbolic links
OrtaCVSS 6,5İstismar yokEPSS %0weblate · weblate18 Ara 2025
- CVE-2017-553722İzleyin
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with
OrtaCVSS 5,3İstismar yokEPSS %2weblate · weblate15 Mar 2017
- CVE-2026-2225122İzleyin
wlc may leak API keys due to an insecure API key configuration
OrtaCVSS 5,5İstismar yokEPSS %0weblate · wlc12 Oca 2026
- CVE-2026-2225022İzleyin
wlc can skip SSL verification
OrtaCVSS 5,5İstismar yokEPSS %0weblate · wlc12 Oca 2026
- CVE-2022-2471021İzleyin
Cross-site Scripting in Weblate
OrtaCVSS 5,4İstismar yokEPSS %1weblate · weblate25 Şub 2022
- CVE-2026-4165421İzleyin
Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
OrtaCVSS 5,3İstismar yokEPSS %0weblate · weblate7 May 2026
- CVE-2026-4151921İzleyin
Weblate's API Token Not Invalidated on Password Change
OrtaCVSS 5,4İstismar yokEPSS %0weblate · weblate7 May 2026
- CVE-2024-3930321İzleyin
Weblate vulnerabler to improper sanitization of project backups
OrtaCVSS 5,4İstismar yokEPSS %0weblate · weblate1 Tem 2024
- CVE-2025-6749221İzleyin
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
OrtaCVSS 5,3İstismar yokEPSS %0weblate · weblate15 Ara 2025
- CVE-2026-4025620İzleyin
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
OrtaCVSS 5,0İstismar yokEPSS %0weblate · weblate15 Nis 2026
- CVE-2026-3424420İzleyin
Weblate: SSRF via Project-Level Machinery Configuration
OrtaCVSS 5,0İstismar yokEPSS %0weblate · weblate15 Nis 2026
- CVE-2026-3344020İzleyin
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
OrtaCVSS 5,0İstismar yokEPSS %0weblate · weblate15 Nis 2026
- CVE-2025-6640720İzleyin
Weblate has Server-Side Request Forgery vulnerability
OrtaCVSS 5,0İstismar yokEPSS %0weblate · weblate15 Ara 2025
- CVE-2026-4215019İzleyin
wlc: print_html outputs API data without HTML escaping, enabling stored XSS
OrtaCVSS 4,8İstismar yokEPSS %0weblate · wlc8 May 2026
- CVE-2025-4795119İzleyin
Weblate lacks rate limiting when verifying second factor
OrtaCVSS 4,9İstismar yokEPSS %0weblate · weblate16 Haz 2025
- CVE-2026-2745717İzleyin
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
OrtaCVSS 4,3İstismar yokEPSS %0weblate · weblate26 Şub 2026