Vulnerabilities
CVE-2025-68398
Weblate is vulnerable to RCE through Git config file overwrite
CVE-2025-68398
Weblate is vulnerable to RCE through Git config file overwrite
CVE-2026-45106
Weblate: Stored HTML injection in editor search preview
CVE-2017-5537
CVE-2017-5537
CVE-2025-32021
CVE-2025-32021
CVE-2025-32021
VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintext
CVE-2025-67492
Weblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration
CVE-2025-67715
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)
CVE-2026-34393
Weblate: Privilege escalation in the user API endpoint
CVE-2026-33435
Weblate: Remote code execution during backup restoration
CVE-2026-33220
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
CVE-2026-39845
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
CVE-2026-33214
Weblate: Improper access control for the translation memory in API
CVE-2025-64326
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
CVE-2025-66407
Weblate has a Server-Side Request Forgery issue
CVE-2026-39845
CVE-2026-39845
CVE-2026-34393
CVE-2026-34393
CVE-2026-33435
CVE-2026-33435
CVE-2026-33220
CVE-2026-33220
CVE-2026-33214
CVE-2026-33214
CVE-2025-67715
CVE-2025-67715
CVE-2025-67492
CVE-2025-67492
CVE-2025-66407
CVE-2025-66407
CVE-2025-64326
CVE-2025-64326
CVE-2026-41519
Weblate Doesn't Invalidate API Token on Password Change
CVE-2026-41654
Weblate Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url
CVE-2026-44264
Weblate vulnerable to XSS via crafted Markdown
CVE-2026-44263
Weblate Vulnerable to Private Translation Enumeration via Screenshot API
CVE-2026-40256
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
CVE-2026-34244
Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-34242
Weblate: Arbitrary File Read via Symlink
CVE-2026-33440
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
CVE-2026-33212
Weblate: Improper access control for pending tasks in API
CVE-2026-27457
Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-24126
Weblate has an argument injection in management console
CVE-2022-23915
Duplicate Advisory: Command injection in Weblate
CVE-2026-21889
Weblate leaks information via screenshots
CVE-2025-68279
Weblate has an arbitrary file read via symbolic links
CVE-2025-64725
Weblate has improper validation upon invitation acceptance
CVE-2025-58352
Weblate has a long session expiry when verifying second factor
CVE-2025-49134
Weblate exposes personal IP address via e-mail
CVE-2025-47951
Weblate lacks rate limiting when verifying second factor
CVE-2024-39303
Weblate vulnerable to improper sanitization of project backups
CVE-2022-23915
Improper Neutralization of Special Elements used in a Command ('Command Injection') in Weblate
CVE-2022-24710
Cross-site Scripting in Weblate
CVE-2017-5537
Weblate user account enumeration via reset password form
CVE-2022-24710
CVE-2022-24710
CVE-2022-23915
CVE-2022-23915
CVE-2022-23915
CVE-2022-23915
Ready to move
Start Securing
Free, no credit card | First findings in minutes