weblate records
37 published records for vendor weblate.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 100%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4
- CWE-284 Improper Access Control3
- CWE-88 Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')2
- CWE-613 Insufficient Session Expiration2
- CWE-20 Improper Input Validation2
The weakness classes this vendor ships most often: where to look.
CWEBug bounty scope
The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.
All records
37 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
36Monitor | CVE-2022-23915No exploit | Remote Code Execution (RCE)weblate · weblate · CWE-88 | High8.8 | — | 3.9% | Mar 4, 2022 |
36Monitor | CVE-2025-68398No exploit | Weblate has git config file overwrite vulnerability that leads to remote code executionweblate · weblate · CWE-20 | Critical9.1 | — | 0.8% | Dec 18, 2025 |
36Monitor | CVE-2026-24126Proof of concept | Weblate has an argument injection in management consoleweblate · weblate · CWE-88 | Critical9.1 | — | 0.5% | Feb 18, 2026 |
35Monitor | CVE-2026-34393No exploit | Weblate: Privilege escalation in the user API endpointweblate · weblate · CWE-269 | High8.8 | — | 0.5% | Apr 15, 2026 |
32Monitor | CVE-2026-33435No exploit | Weblate: Remote code execution during backup restorationweblate · weblate · CWE-23 | High8.0 | — | 0.9% | Apr 15, 2026 |
32Monitor | CVE-2026-23535No exploit | wlc Path traversal: Unsanitized API slugs in download commandweblate · wlc · CWE-22 | High8.0 | — | 0.4% | Jan 16, 2026 |
30Monitor | CVE-2026-34242No exploit | Weblate: Arbitrary File Read via Symlinkweblate · weblate · CWE-22 | High7.7 | — | 0.5% | Apr 15, 2026 |
30Monitor | CVE-2025-32021No exploit | Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintextweblate · weblate · CWE-598 | High7.5 | — | 0.4% | Apr 15, 2025 |
27Monitor | CVE-2026-33220No exploit | Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryweblate · weblate · CWE-22 | Medium6.8 | — | 0.4% | Apr 15, 2026 |
26Monitor | CVE-2025-68279No exploit | Weblate has an arbitrary file read via symbolic linksweblate · weblate · CWE-22 | Medium6.5 | — | 0.4% | Dec 18, 2025 |
22Monitor | CVE-2017-5537No exploit | The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated withweblate · weblate · CWE-200 | Medium5.3 | — | 2.3% | Mar 15, 2017 |
22Monitor | CVE-2026-22251No exploit | wlc may leak API keys due to an insecure API key configurationweblate · wlc · CWE-200 | Medium5.5 | — | 0.2% | Jan 12, 2026 |
22Monitor | CVE-2026-22250No exploit | wlc can skip SSL verificationweblate · wlc · CWE-295 | Medium5.5 | — | 0.2% | Jan 12, 2026 |
21Monitor | CVE-2022-24710No exploit | Cross-site Scripting in Weblateweblate · weblate · CWE-79 | Medium5.4 | — | 0.8% | Feb 25, 2022 |
21Monitor | CVE-2026-41654No exploit | Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlweblate · weblate · CWE-20 | Medium5.3 | — | 0.5% | May 7, 2026 |
21Monitor | CVE-2026-41519No exploit | Weblate's API Token Not Invalidated on Password Changeweblate · weblate · CWE-613 | Medium5.4 | — | 0.4% | May 7, 2026 |
21Monitor | CVE-2024-39303No exploit | Weblate vulnerabler to improper sanitization of project backupsweblate · weblate · CWE-73 | Medium5.4 | — | 0.3% | Jul 1, 2024 |
21Monitor | CVE-2025-67492No exploit | Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumerationweblate · weblate · CWE-1286 | Medium5.3 | — | 0.3% | Dec 15, 2025 |
20Monitor | CVE-2026-40256No exploit | Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collisionweblate · weblate · CWE-22 | Medium5.0 | — | 0.4% | Apr 15, 2026 |
20Monitor | CVE-2026-34244No exploit | Weblate: SSRF via Project-Level Machinery Configurationweblate · weblate · CWE-200 | Medium5.0 | — | 0.3% | Apr 15, 2026 |
20Monitor | CVE-2026-33440No exploit | Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsweblate · weblate · CWE-918 | Medium5.0 | — | 0.3% | Apr 15, 2026 |
20Monitor | CVE-2025-66407No exploit | Weblate has Server-Side Request Forgery vulnerabilityweblate · weblate · CWE-352 | Medium5.0 | — | 0.2% | Dec 15, 2025 |
19Monitor | CVE-2026-42150No exploit | wlc: print_html outputs API data without HTML escaping, enabling stored XSSweblate · wlc · CWE-79 | Medium4.8 | — | 0.3% | May 8, 2026 |
19Monitor | CVE-2025-47951No exploit | Weblate lacks rate limiting when verifying second factorweblate · weblate · CWE-307 | Medium4.9 | — | 0.3% | Jun 16, 2025 |
17Monitor | CVE-2026-27457No exploit | Weblate: Missing access control for the AddonViewSet API exposes all addon configurationsweblate · weblate · CWE-200 | Medium4.3 | — | 0.4% | Feb 26, 2026 |
- CVE-2022-2391536Monitor
Remote Code Execution (RCE)
HighCVSS 8.8No exploitEPSS 4%weblate · weblateMar 4, 2022
- CVE-2025-6839836Monitor
Weblate has git config file overwrite vulnerability that leads to remote code execution
CriticalCVSS 9.1No exploitEPSS 1%weblate · weblateDec 18, 2025
- CVE-2026-2412636Monitor
Weblate has an argument injection in management console
CriticalCVSS 9.1Proof of conceptEPSS 0%weblate · weblateFeb 18, 2026
- CVE-2026-3439335Monitor
Weblate: Privilege escalation in the user API endpoint
HighCVSS 8.8No exploitEPSS 1%weblate · weblateApr 15, 2026
- CVE-2026-3343532Monitor
Weblate: Remote code execution during backup restoration
HighCVSS 8.0No exploitEPSS 1%weblate · weblateApr 15, 2026
- CVE-2026-2353532Monitor
wlc Path traversal: Unsanitized API slugs in download command
HighCVSS 8.0No exploitEPSS 0%weblate · wlcJan 16, 2026
- CVE-2026-3424230Monitor
Weblate: Arbitrary File Read via Symlink
HighCVSS 7.7No exploitEPSS 1%weblate · weblateApr 15, 2026
- CVE-2025-3202130Monitor
Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
HighCVSS 7.5No exploitEPSS 0%weblate · weblateApr 15, 2025
- CVE-2026-3322027Monitor
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
MediumCVSS 6.8No exploitEPSS 0%weblate · weblateApr 15, 2026
- CVE-2025-6827926Monitor
Weblate has an arbitrary file read via symbolic links
MediumCVSS 6.5No exploitEPSS 0%weblate · weblateDec 18, 2025
- CVE-2017-553722Monitor
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with
MediumCVSS 5.3No exploitEPSS 2%weblate · weblateMar 15, 2017
- CVE-2026-2225122Monitor
wlc may leak API keys due to an insecure API key configuration
MediumCVSS 5.5No exploitEPSS 0%weblate · wlcJan 12, 2026
- CVE-2026-2225022Monitor
wlc can skip SSL verification
MediumCVSS 5.5No exploitEPSS 0%weblate · wlcJan 12, 2026
- CVE-2022-2471021Monitor
Cross-site Scripting in Weblate
MediumCVSS 5.4No exploitEPSS 1%weblate · weblateFeb 25, 2022
- CVE-2026-4165421Monitor
Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
MediumCVSS 5.3No exploitEPSS 0%weblate · weblateMay 7, 2026
- CVE-2026-4151921Monitor
Weblate's API Token Not Invalidated on Password Change
MediumCVSS 5.4No exploitEPSS 0%weblate · weblateMay 7, 2026
- CVE-2024-3930321Monitor
Weblate vulnerabler to improper sanitization of project backups
MediumCVSS 5.4No exploitEPSS 0%weblate · weblateJul 1, 2024
- CVE-2025-6749221Monitor
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
MediumCVSS 5.3No exploitEPSS 0%weblate · weblateDec 15, 2025
- CVE-2026-4025620Monitor
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
MediumCVSS 5.0No exploitEPSS 0%weblate · weblateApr 15, 2026
- CVE-2026-3424420Monitor
Weblate: SSRF via Project-Level Machinery Configuration
MediumCVSS 5.0No exploitEPSS 0%weblate · weblateApr 15, 2026
- CVE-2026-3344020Monitor
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
MediumCVSS 5.0No exploitEPSS 0%weblate · weblateApr 15, 2026
- CVE-2025-6640720Monitor
Weblate has Server-Side Request Forgery vulnerability
MediumCVSS 5.0No exploitEPSS 0%weblate · weblateDec 15, 2025
- CVE-2026-4215019Monitor
wlc: print_html outputs API data without HTML escaping, enabling stored XSS
MediumCVSS 4.8No exploitEPSS 0%weblate · wlcMay 8, 2026
- CVE-2025-4795119Monitor
Weblate lacks rate limiting when verifying second factor
MediumCVSS 4.9No exploitEPSS 0%weblate · weblateJun 16, 2025
- CVE-2026-2745717Monitor
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
MediumCVSS 4.3No exploitEPSS 0%weblate · weblateFeb 26, 2026