Skip to content
Noroxi

weblate records

37 published records for vendor weblate.

Bug bounty scope

The product’s vendor appears in a public program. Matched by name; verify the scope text in the program.

All records

37 records
  • Remote Code Execution (RCE)

    HighCVSS 8.8No exploitEPSS 4%

    weblate · weblateMar 4, 2022

  • Weblate has git config file overwrite vulnerability that leads to remote code execution

    CriticalCVSS 9.1No exploitEPSS 1%

    weblate · weblateDec 18, 2025

  • Weblate has an argument injection in management console

    CriticalCVSS 9.1Proof of conceptEPSS 0%

    weblate · weblateFeb 18, 2026

  • Weblate: Privilege escalation in the user API endpoint

    HighCVSS 8.8No exploitEPSS 1%

    weblate · weblateApr 15, 2026

  • Weblate: Remote code execution during backup restoration

    HighCVSS 8.0No exploitEPSS 1%

    weblate · weblateApr 15, 2026

  • wlc Path traversal: Unsanitized API slugs in download command

    HighCVSS 8.0No exploitEPSS 0%

    weblate · wlcJan 16, 2026

  • Weblate: Arbitrary File Read via Symlink

    HighCVSS 7.7No exploitEPSS 1%

    weblate · weblateApr 15, 2026

  • Weblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext

    HighCVSS 7.5No exploitEPSS 0%

    weblate · weblateApr 15, 2025

  • Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository

    MediumCVSS 6.8No exploitEPSS 0%

    weblate · weblateApr 15, 2026

  • Weblate has an arbitrary file read via symbolic links

    MediumCVSS 6.5No exploitEPSS 0%

    weblate · weblateDec 18, 2025

  • CVE-2017-5537
    22Monitor

    The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with

    MediumCVSS 5.3No exploitEPSS 2%

    weblate · weblateMar 15, 2017

  • wlc may leak API keys due to an insecure API key configuration

    MediumCVSS 5.5No exploitEPSS 0%

    weblate · wlcJan 12, 2026

  • wlc can skip SSL verification

    MediumCVSS 5.5No exploitEPSS 0%

    weblate · wlcJan 12, 2026

  • Cross-site Scripting in Weblate

    MediumCVSS 5.4No exploitEPSS 1%

    weblate · weblateFeb 25, 2022

  • Weblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

    MediumCVSS 5.3No exploitEPSS 0%

    weblate · weblateMay 7, 2026

  • Weblate's API Token Not Invalidated on Password Change

    MediumCVSS 5.4No exploitEPSS 0%

    weblate · weblateMay 7, 2026

  • Weblate vulnerabler to improper sanitization of project backups

    MediumCVSS 5.4No exploitEPSS 0%

    weblate · weblateJul 1, 2024

  • Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration

    MediumCVSS 5.3No exploitEPSS 0%

    weblate · weblateDec 15, 2025

  • Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

    MediumCVSS 5.0No exploitEPSS 0%

    weblate · weblateApr 15, 2026

  • Weblate: SSRF via Project-Level Machinery Configuration

    MediumCVSS 5.0No exploitEPSS 0%

    weblate · weblateApr 15, 2026

  • Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

    MediumCVSS 5.0No exploitEPSS 0%

    weblate · weblateApr 15, 2026

  • Weblate has Server-Side Request Forgery vulnerability

    MediumCVSS 5.0No exploitEPSS 0%

    weblate · weblateDec 15, 2025

  • wlc: print_html outputs API data without HTML escaping, enabling stored XSS

    MediumCVSS 4.8No exploitEPSS 0%

    weblate · wlcMay 8, 2026

  • Weblate lacks rate limiting when verifying second factor

    MediumCVSS 4.9No exploitEPSS 0%

    weblate · weblateJun 16, 2025

  • Weblate: Missing access control for the AddonViewSet API exposes all addon configurations

    MediumCVSS 4.3No exploitEPSS 0%

    weblate · weblateFeb 26, 2026