weblate
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 47 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from March 15, 2017 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →Weblate: DNS rebinding in VCS operations allows server-side request forgery
Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users
Weblate Has Uncontrolled Resource Consumption via
Weblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpoint
Weblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)
Weblate: Team-enforced 2FA is bypassed for global permissions
Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private project
Observable object existence disclosure in private Weblate projects via globally scoped object lookups
Weblate: Unverified REST API email changes
Weblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)
Monitor weblate in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.