weblate
A web-based continuous localization system with tight version control integration
Activity
- Latest release
- 6d ago
- Total releases
- 172
- Cadence
- ~12 days
- Last 12 months
- 21
Details
- License
- unknown
- First release
- Dec 11, 2014
| Version | Released | |
|---|---|---|
2026.9.1
patch
|
2026.9.1
patch
Dependencies (108)
+ 100 more |
|
2026.9
minor
|
2026.9
minor
Dependencies (108)
+ 100 more |
|
2026.8.1
patch
|
2026.8.1
patch
Dependencies (106)
+ 98 more |
|
2026.8
minor
|
2026.8
minor
Dependencies (106)
+ 98 more |
|
2026.7.1
patch
|
2026.7.1
patch
Dependencies (105)
+ 97 more |
|
2026.7
minor
|
2026.7
minor
Dependencies (105)
+ 97 more |
|
2026.6.1
patch
2 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2026.6.1
patch
Dependencies (105)
+ 97 more |
|
2026.6
minor
2 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev |
2026.6
minor
Dependencies (105)
+ 97 more |
|
2026.5
major
3 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev |
2026.5
major
Dependencies (97)
+ 89 more |
|
5.17.1
patch
4 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.17.1
patch
Dependencies (86)
+ 78 more |
|
5.17
minor
8 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev |
5.17
minor
Dependencies (86)
+ 78 more |
|
5.16.2
patch
18 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev |
5.16.2
patch
Dependencies (92)
+ 84 more |
|
5.16.1
patch
18 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev |
5.16.1
patch
Dependencies (92)
+ 84 more |
|
5.16
minor
19 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.16
minor
Dependencies (92)
+ 84 more |
|
5.15.2
patch
20 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev |
5.15.2
patch
Dependencies (92)
+ 84 more |
|
5.15.1
patch
21 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev |
5.15.1
patch
Dependencies (92)
+ 84 more |
|
5.15
minor
23 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-50127
PYSEC-2026-3416
GHSA-vmfc-9982-2m45
Jul 13, 2026
Weblate SSRF: outbound URL guard misses some private ranges
5.9
/ 10
Medium
Network
High
None
None
Unchanged
High
None
None
ImpactWeblate's Patches
ResourcesThe issue was reported by @tonghuaroot via GitHub, and the same user also provided the initial patch. Affected versions
2026.5
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
Fixed in
2026.6
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev |
5.15
minor
Dependencies (92)
+ 84 more |
|
5.14.3
patch
26 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev |
5.14.3
patch
Dependencies (89)
+ 81 more |
|
5.14.2
patch
26 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev |
5.14.2
patch
Dependencies (89)
+ 81 more |
|
5.14.1
patch
26 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev |
5.14.1
patch
Dependencies (89)
+ 81 more |
|
5.14
minor
27 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev |
5.14
minor
Dependencies (89)
+ 81 more |
|
5.13.3
patch
27 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev |
5.13.3
patch
Dependencies (89)
+ 81 more |
|
5.13.2
patch
28 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.13.2
patch
Dependencies (89)
+ 81 more |
|
5.13.1
patch
28 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.13.1
patch
Dependencies (89)
+ 81 more |
|
5.13
minor
29 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.13
minor
Dependencies (90)
+ 82 more |
|
5.12.2
patch
29 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.12.2
patch
Dependencies (89)
+ 81 more |
|
5.12.1
minor
29 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.12.1
minor
Dependencies (89)
+ 81 more |
|
5.11.4
patch
31 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.11.4
patch
Dependencies (88)
+ 80 more |
|
5.11.3
patch
31 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.11.3
patch
Dependencies (88)
+ 80 more |
|
5.11.1
patch
31 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.11.1
patch
Dependencies (88)
+ 80 more |
|
5.11
minor
31 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev |
5.11
minor
Dependencies (88)
+ 80 more |
|
5.10.4
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.10.4
patch
Dependencies (87)
+ 79 more |
|
5.10.3
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.10.3
patch
Dependencies (87)
+ 79 more |
|
5.10.2
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.10.2
patch
Dependencies (87)
+ 79 more |
|
5.10.1
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.10.1
patch
Dependencies (87)
+ 79 more |
|
5.10
minor
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.10
minor
Dependencies (86)
+ 78 more |
|
5.9.2
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.9.2
patch
Dependencies (84)
+ 76 more |
|
5.9.1
minor
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.9.1
minor
Dependencies (84)
+ 76 more |
|
5.8.4
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.8.4
patch
Dependencies (101)
+ 93 more |
|
5.8.3
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.8.3
patch
Dependencies (101)
+ 93 more |
|
5.8.2
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.8.2
patch
Dependencies (101)
+ 93 more |
|
5.8.1
minor
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.8.1
minor
Dependencies (102)
+ 94 more |
|
5.7.2
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.7.2
patch
Dependencies (101)
+ 93 more |
|
5.7.1
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.7.1
patch
Dependencies (102)
+ 94 more |
|
5.7
minor
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.7
minor
Dependencies (102)
+ 94 more |
|
5.6.2
patch
32 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.6.2
patch
Dependencies (96)
+ 88 more |
|
5.6.1
patch
33 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39303
PYSEC-2026-2041
GHSA-jfgp-674x-6q4p
Jul 07, 2026
Weblate vulnerable to improper sanitization of project backups
Medium
Network
Low
High
None
ImpactWeblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. PatchesThis issue has been addressed in Weblate 5.6.2 via https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd. WorkaroundsDo not allow project creation to untrusted users. ReferencesThanks to Bryan Cahill for bringing this issue to our attention. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
+ 23 more Show less
4.18
4.18.1
4.18.2
5.0
5.0.1
5.0.2
5.1
5.1.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
Fixed in
5.6.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.6.1
patch
Dependencies (96)
+ 88 more |
|
5.6
minor
33 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39303
PYSEC-2026-2041
GHSA-jfgp-674x-6q4p
Jul 07, 2026
Weblate vulnerable to improper sanitization of project backups
Medium
Network
Low
High
None
ImpactWeblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. PatchesThis issue has been addressed in Weblate 5.6.2 via https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd. WorkaroundsDo not allow project creation to untrusted users. ReferencesThanks to Bryan Cahill for bringing this issue to our attention. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
+ 23 more Show less
4.18
4.18.1
4.18.2
5.0
5.0.1
5.0.2
5.1
5.1.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
Fixed in
5.6.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.6
minor
Dependencies (96)
+ 88 more |
|
5.5.5
patch
33 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39303
PYSEC-2026-2041
GHSA-jfgp-674x-6q4p
Jul 07, 2026
Weblate vulnerable to improper sanitization of project backups
Medium
Network
Low
High
None
ImpactWeblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. PatchesThis issue has been addressed in Weblate 5.6.2 via https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd. WorkaroundsDo not allow project creation to untrusted users. ReferencesThanks to Bryan Cahill for bringing this issue to our attention. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
+ 23 more Show less
4.18
4.18.1
4.18.2
5.0
5.0.1
5.0.2
5.1
5.1.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
Fixed in
5.6.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.5.5
patch
Dependencies (99)
+ 91 more |
|
5.5.4
patch
33 CVEs
CVE-2026-55228
PYSEC-2026-3942
GHSA-2q2q-jr9g-v9rf
Sep 10, 2026
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
ImpactThe API did not properly handle project- and workspace-scoped teams and allowed setting invalid configurations, including granting access to projects the user has no access to. Patches
ReferencesParts of this issue were independently reported by four reporters: Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-55227
PYSEC-2026-3941
GHSA-2p9g-x3cv-5hh4
Sep 10, 2026
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
ImpactThe several endpoints could leak object existence information to users who had no access to it by HTTP status code 403 instead of 404. Patches
ReferencesThanks to Yaohui Wang for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 156 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
2026.5
2026.6
2026.6.1
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.7
References
Updated Sep 10, 2026 · Source: OSV.dev
CVE-2026-45106
PYSEC-2026-3415
GHSA-6wxc-8mgq-w26m
Jul 13, 2026
Weblate: Stored HTML injection in editor search preview
4.6
/ 10
Medium
Network
Low
Low
Required
Unchanged
Low
Low
None
ImpactWeblate's live search preview renders unit Patches
WorkaroundsOnly the search preview on the selected views is affected. ResourcesWeblate thanks @adrgs for reporting this issue responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 153 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.17.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
2026.5
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-21889
PYSEC-2026-2037
GHSA-3g2f-4rjg-9385
Jul 07, 2026
Weblate leaks information via screenshots
Medium
Network
High
Low
None
ImpactThe screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthenticated user to access screenshots after guessing their filename. Patches
ReferencesThanks to Lukas May and Michael Leu for reporting this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 147 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68279
PYSEC-2026-2040
GHSA-g925-f788-4jh7
Jul 07, 2026
Weblate has an arbitrary file read via symbolic links
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactIt was possible to read arbitrary files from the server file system using crafted symbolic links in the repository. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-64725
PYSEC-2026-2042
GHSA-m6hq-f4w9-qrjj
Jul 07, 2026
Weblate has improper validation upon invitation acceptance
Medium
Local
High
Low
ImpactIt was possible to accept an invitation opened by a different Weblate user. Patches
WorkaroundsUsers should avoid leaving Weblate sessions with an unattended opened invitation. ReferencesThanks to Nahid0x for responsibly disclosing this vulnerability to Weblate. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-58352
PYSEC-2026-2036
GHSA-377j-wj38-4728
Jul 07, 2026
Weblate has a long session expiry when verifying second factor
Medium
Network
High
Low
ImpactThe verification of the second factor had too long a session expiry. The long session expiry could be used to circumvent rate limiting of the second factor. PatchesThis issue has been addressed in Weblate 5.13.1 via https://github.com/WeblateOrg/weblate/pull/16002. ReferencesThanks to Nahid Hasan Limon for reporting this issue responsibly. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 138 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.1
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-49134
PYSEC-2026-2038
GHSA-4qqf-9m5c-w2c5
Jul 07, 2026
Weblate exposes personal IP address via e-mail
Low
Network
High
High
None
ImpactThe audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/15102. ReferencesThanks to micael1 for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-47951
PYSEC-2026-2039
GHSA-57jg-m997-cx3q
Jul 07, 2026
Weblate lacks rate limiting when verifying second factor
4.9
/ 10
Medium
Network
High
Low
None
Changed
Low
Low
None
ImpactThe verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. PatchesThis issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918. ReferencesThanks to obscuredeer for reporting this issue at HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 135 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.12
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2024-39303
PYSEC-2026-2041
GHSA-jfgp-674x-6q4p
Jul 07, 2026
Weblate vulnerable to improper sanitization of project backups
Medium
Network
Low
High
None
ImpactWeblate didn't correctly validate filenames when restoring project backup. It may be possible to gain unauthorized access to files on the server using a crafted ZIP file. PatchesThis issue has been addressed in Weblate 5.6.2 via https://github.com/WeblateOrg/weblate/commit/b6a7eace155fa0feaf01b4ac36165a9c5e63bfdd. WorkaroundsDo not allow project creation to untrusted users. ReferencesThanks to Bryan Cahill for bringing this issue to our attention. For more informationIf you have any questions or comments about this advisory:
Affected versions
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
+ 23 more Show less
4.18
4.18.1
4.18.2
5.0
5.0.1
5.0.2
5.1
5.1.1
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
Fixed in
5.6.2
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-68398
PYSEC-2026-571
GHSA-8vcg-cfxj-p5m3
Jun 29, 2026
Weblate is vulnerable to RCE through Git config file overwrite
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
ImpactIt was possible to overwrite Git configuration remotely and override some of its behavior. ResourcesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 146 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15.1
References
Updated Jul 01, 2026 · Source: OSV.dev
CVE-2025-66407
GHSA-hfpv-mc5v-p9mm
PYSEC-2025-231
May 26, 2026
Weblate has a Server-Side Request Forgery issue
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe Create Component functionality in Weblate allows authorized users to add new translation components by specifying both a version control system and a source code repository URL to pull from. However, the repository URL field is not validated or sanitized, allowing an attacker to supply arbitrary protocols, hostnames, and IP addresses, including localhost, internal network addresses, and local filenames. When the Mercurial version control system is selected, Weblate exposes the full server-side HTTP response for the provided URL. This effectively creates a server-side request forgery (SSRF) primitive that can probe internal services and return their contents. In addition to accessing internal HTTP endpoints, the behavior also enables local file enumeration by attempting file:// requests. While file contents may not always be returned, the application’s error messages clearly differentiate between files that exist and files that do not, revealing information about the server’s filesystem layout. In cloud environments, this behavior is particularly dangerous, as internal-only endpoints such as cloud metadata services may be accessible, potentially leading to credential disclosure and full environment compromise. PatchesThis has been addressed in the Weblate 5.15 release.
WorkaroundsRemoving Mercurial from VCS_BACKENDS avoids this vulnerability, as the Git backend is not affected. The Git backend was already configured to block the file protocol and does not expose the HTTP response content in the error message. ReferencesThanks to Jason Marcello for responsible disclosure. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References
Updated May 26, 2026 · Source: OSV.dev
CVE-2026-44264
PYSEC-2026-2319
GHSA-5cmv-3rc4-7279
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-44263
PYSEC-2026-2318
GHSA-gcg5-86jr-f7jg
May 07, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowed for the enumeration of translations in a project inaccessible to the user. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41654
PYSEC-2026-2317
GHSA-cwcx-382v-8m9g
May 07, 2026
8.1
/ 10
High
Network
Low
Low
None
Unchanged
High
High
None
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an active billing/trial plan) can import a crafted project backup ZIP whose components/.json contains an attacker-chosen repo URL pointing at a private address (e.g. http://127.0.0.1:9999/) or using a non-allow-listed scheme (e.g. file://, git://). Weblate persists the component via Component.objects.bulk_create([component])[0], which bypasses Django's full_clean() and therefore never runs the validate_repo_url validator. The URL is subsequently written verbatim into .git/config by configure_repo(pull=False). This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-41519
PYSEC-2026-2316
GHSA-6j8j-4qp3-36p2
May 07, 2026
5.4
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
None
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions are correctly invalidated via "cycle_session_keys()", but DRF API tokens ("wlu_*" prefix) stored in "authtoken_token" are not revoked. This issue has been patched in version 5.17.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 152 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.17
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17.1
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-40256
GHSA-ffgh-3jrf-8wvh
PYSEC-2026-2315
Apr 16, 2026
Weblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactWeblate repository-boundary validation relies on string prefix checks on resolved absolute paths. In multiple code paths, the check uses startswith against the repository root path. This is not path-segment aware and can be bypassed when the external path shares the same string prefix as the repository path (for example, repo and repo_outside). Patches
ReferencesThanks to m9nx4u for reporting this issue via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-39845
GHSA-f8hv-g549-hwg2
PYSEC-2026-156
Apr 16, 2026
Weblate: SSRF via the webhook add-on using unprotected fetch_url()
4.1
/ 10
Medium
Network
Low
High
None
Changed
Low
None
None
ImpactThe webhook add-on did not utilize existing SSRF protection. Patches
WorkaroundsDisabling the add-on would avoid misusing this. ReferencesThanks to @Lihfdgjr for reporting this via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34393
GHSA-3382-gw9x-477v
PYSEC-2026-155
Apr 16, 2026
Weblate: Privilege escalation in the user API endpoint
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
ImpactThe user patching API endpoint didn't properly limit the scope of edits. Patches
ReferencesThanks to @tikket1 and @DavidCarliez for reporting this via GitHub. We received two individual reports for this. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-34244
GHSA-xrwr-fcw6-fmq8
PYSEC-2026-2314
Apr 16, 2026
Weblate: SSRF via Project-Level Machinery Configuration
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactA user with the Patches
WorkaroundsLimiting available machinery services via WEBLATE_MACHINERY setting can avoid this. ReferencesThanks to @DavidCarliez for disclosing this via GitHub private vulnerability reporting. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-34242
GHSA-hv99-mxm5-q397
PYSEC-2026-2313
Apr 16, 2026
Weblate: Arbitrary File Read via Symlink
7.7
/ 10
High
Network
Low
Low
None
Changed
High
None
None
ImpactThe ZIP download feature didn't verify downloaded file and it could follow symlinks outside the repository. Patches
ReferencesThanks to @DavidCarliez for reporting this vulnerability via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33440
GHSA-5fhx-9jwj-867m
PYSEC-2026-2312
Apr 16, 2026
Weblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads
5.0
/ 10
Medium
Network
Low
Low
None
Changed
Low
None
None
ImpactThe ALLOWED_ASSET_DOMAINS setting applied only to the first issued requests and didn't restrict possible redirects. Patches
ReferencesThis issue was reported by @spbavarva via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-33435
GHSA-558g-h753-6m33
PYSEC-2026-154
Apr 16, 2026
Weblate: Remote code execution during backup restoration
8.0
/ 10
High
Network
High
High
None
Changed
High
High
High
ImpactThe project backup didn't filter Git and Mercurial configuration files and this could lead to remote code execution under certain circumstances. Patches
WorkaroundsThe project backup is only accessible to users who can create projects. Restricting access to this limits scope of the vulnerability. ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33220
GHSA-mqph-7h49-hqfm
PYSEC-2026-153
Apr 16, 2026
Weblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository
6.8
/ 10
Medium
Network
Low
Low
Required
Changed
High
None
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsThe CDN add-on is not enabled by default. ReferencesThanks to @spbavarva for reporting this responsibly via GitHub. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33214
GHSA-mpf5-3vph-q75r
PYSEC-2026-152
Apr 16, 2026
Weblate: Improper access control for the translation memory in API
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
None
Low
None
ImpactThe translation memory API exposed unintended endpoints, which in turn didn't do proper access control. Patches
WorkaroundsBlocking access to ReferencesThis issue was reported by ggamno via HackerOne. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jun 08, 2026 · Source: OSV.dev
CVE-2026-33212
GHSA-vj45-x3pj-f4w4
PYSEC-2026-2311
Apr 16, 2026
Weblate: Improper access control for pending tasks in API
3.1
/ 10
Low
Network
High
Low
None
Unchanged
Low
None
None
ImpactThe API for tasks didn't verify user access for pending tasks. This could expose logs of in-progress operations to users who don't have access to given scope. Patches
WorkaroundsThe attacker needs to guess the random UUID of the task, so exploiting this is unlikely with the default API rate limits. ReferencesThis issue was identified by Michal Čihař. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 151 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.16.1
5.16.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.17
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-27457
PYSEC-2026-2310
GHSA-wppc-7cq7-cgfv
Feb 26, 2026
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 149 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.16
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16.1
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2026-24126
PYSEC-2026-2309
GHSA-33fm-6gp7-4p47
Feb 19, 2026
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argument injection to Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 148 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.15
5.15.1
5.15.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.16
References Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-67715
PYSEC-2025-233
GHSA-3pmh-24wp-xpf4
Dec 16, 2025
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-67492
PYSEC-2025-232
GHSA-pj86-258h-qrvf
Dec 16, 2025
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to trigger repository updates for many repositories via a crafted webhook payload. Version 5.15 fixes the issue. As a workaround, disabling webhooks completely using ENABLE_HOOKS avoids this vulnerability. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 145 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.14.1
5.14.2
5.14.3
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.15
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-64326
PYSEC-2025-230
GHSA-gr35-vpx2-qxhc
PYSEC-2025-126
Nov 06, 2025
3.5
/ 10
Low
Network
Low
Low
Required
Unchanged
Low
None
None
Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 142 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.13.3
5.14
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.14.1
References Updated May 20, 2026 · Source: OSV.dev
CVE-2025-61587
PYSEC-2025-269
GHSA-3xhv-r4gx-xw99
Oct 01, 2025
6.1
/ 10
Medium
Network
Low
None
Required
Changed
Low
Low
None
Weblate is a web based localization tool. An open redirect exists in versions 5.13.2 and below via the redir parameter on .within.website when Weblate is configured with Anubis and REDIRECT_DOMAINS is not set. An attacker can craft a URL on the legitimate domain that redirects a victim to an attacker-controlled site. The redirect can also be used to initiate drive-by downloads (redirecting to a URL that serves a malicious file), increasing the risk to end users. This issue is fixed in version 5.13.3. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 140 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.11
5.11.1
5.11.3
5.11.4
5.12.1
5.12.2
5.13
5.13.1
5.13.2
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
Fixed in
5.13.3
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-32021
PYSEC-2025-35
GHSA-m67m-3p5g-cw9j
Apr 15, 2025
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
Weblate is a web based localization tool. Prior to version 5.11, when creating a new component from an existing component that has a source code repository URL specified in settings, this URL is included in the client's URL parameters during the creation process. If, for example, the source code repository URL contains GitHub credentials, the confidential PAT and username are shown in plaintext and get saved into browser history. Moreover, if the request URL is logged, the credentials are written to logs in plaintext. If using Weblate official Docker image, nginx logs the URL and the token in plaintext. This issue is patched in version 5.11. Affected versions
1.9
2.0
2.1
2.10
2.10.1
2.11
2.12
2.13
2.13.1
2.14
2.14.1
2.15
+ 132 more Show less
2.16
2.17
2.17.1
2.18
2.19
2.19.1
2.2
2.20
2.3
2.4
2.5
2.6
2.7
2.8
2.9
3.0
3.0.1
3.1
3.1.1
3.10
3.10.1
3.10.2
3.10.3
3.11
3.11.1
3.11.2
3.11.3
3.2
3.2.1
3.2.2
3.3
3.4
3.5
3.5.1
3.6
3.6.1
3.7
3.7.1
3.8
3.9
3.9.1
4.0
4.0.1
4.0.2
4.0.3
4.0.4
4.1
4.1.1
4.10
4.10.1
4.11
4.11.1
4.11.2
4.12
4.12.1
4.12.2
4.13
4.13.1
4.14
4.14.1
4.14.2
4.15
4.15.1
4.15.2
4.16
4.16.1
4.16.2
4.16.3
4.16.4
4.17
4.18
4.18.1
4.18.2
4.2
4.2.1
4.2.2
4.3
4.3.1
4.3.2
4.4
4.4.1
4.4.2
4.5
4.5.1
4.5.2
4.5.3
4.6
4.6.1
4.6.2
4.7
4.7.1
4.7.2
4.8
4.8.1
4.9
4.9.1
5.0
5.0.1
5.0.2
5.1
5.1.1
5.10
5.10.1
5.10.2
5.10.3
5.10.4
5.2
5.2.1
5.3
5.3.1
5.4
5.4.1
5.4.2
5.4.3
5.5
5.5.2
5.5.3
5.5.4
5.5.5
5.6
5.6.1
5.6.2
5.7
5.7.1
5.7.2
5.8.1
5.8.2
5.8.3
5.8.4
5.9.1
5.9.2
5.9.dev0
Fixed in
5.11
References Updated Jun 10, 2026 · Source: OSV.dev |
5.5.4
patch
Dependencies (99)
+ 91 more |