Security: WeblateOrg/weblate
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Uncontrolled Resource Consumption in WeblateGHSA-r52j-4vjp-q949 published
Jul 11, 2026 by nijelModerate -
Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpointGHSA-92m8-wv36-prmx published
Jul 11, 2026 by nijelModerate -
Incomplete Fix of CVE-2026-34242: appstore ZIP download still follows child symlinksGHSA-xwj4-fp82-r2rj published
Jul 11, 2026 by nijelHigh -
Team-enforced 2FA is bypassed for global permissionsGHSA-x86c-ff69-cr2m published
Jul 11, 2026 by nijelModerate -
Observable object existence disclosure in private Weblate projects via globally scoped object lookupsGHSA-2p9g-x3cv-5hh4 published
Jul 11, 2026 by nijelModerate -
GroupViewSet allows authenticated project manager to gain unauthorized read access to any private projectGHSA-2q2q-jr9g-v9rf published
Jul 11, 2026 by nijelHigh -
Weblate SSRF: outbound URL guard misses some private rangesGHSA-vmfc-9982-2m45 published
Jun 1, 2026 by nijelModerate -
Stored HTML injection in editor search previewGHSA-6wxc-8mgq-w26m published
May 15, 2026 by nijelModerate -
XSS via crafted MarkdownGHSA-5cmv-3rc4-7279 published
Apr 30, 2026 by nijelModerate -
Private Translation Enumeration via Screenshot APIGHSA-gcg5-86jr-f7jg published
Apr 30, 2026 by nijelModerate