Weblate
21 known vulnerabilities
Top Products
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc emb
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other
Weblate is a web based localization tool. Prior to version 5.17.1, the screenshots, tasks, and component link API allowe
Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (de
Weblate is a web based localization tool. Prior to version 5.17.1, when a user changes their password, browser sessions
Weblate is a web based localization tool. In versions prior to 5.17, repository-boundary validation relies on string pre
Weblate is a web based localization tool. In versions prior to 5.17, the webhook add-on did not utilize existing SSRF pr
Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limi
Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by
Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded f
Weblate is a web based localization tool. In versions prior to 5.17, the ALLOWED_ASSET_DOMAINS setting applied only to t
Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo
Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpo
Weblate is a web based localization tool. In versions prior to 5.17, the tasks API didn't verify user access for pending
Weblate is a web based localization tool. Prior to version 5.16.1, the REST API's `AddonViewSet` (`weblate/api/views.py`
Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could wri
Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API key
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped fo
Frequently Asked Questions
How many CVEs affect Weblate?
Weblate has 21 CVE records in our database, including 0 critical and 6 high severity vulnerabilities.
What are the most severe Weblate vulnerabilities?
Weblate has 0 critical severity (CVSS 9.0+) and 6 high severity (CVSS 7.0-8.9) vulnerabilities. Review the list above sorted by publication date to find the most recent high-severity issues.
How can I scan for Weblate vulnerabilities?
CyberStrike's AI-powered security agents automatically detect vulnerabilities in Weblate products across your infrastructure. The platform provides continuous pentesting, DAST scanning, and real-time vulnerability monitoring with actionable remediation guidance.
Detect Weblate Vulnerabilities
CyberStrike scans your infrastructure for Weblate vulnerabilities and provides real-time remediation guidance.
Get Started