Where
-Infinity
0

Vendor Risk Score

See how weblate compares to other vendors in security performance

View Risk Score →

Weblate weblateWeblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)

Risk 35
Severity
5.9
First published (updated )

Weblate wlcwlc: print_html outputs API data without HTML escaping, enabling stored XSS

Risk 36
Severity
5.1
First published (updated )

pip/weblateWeblate is vulnerable to XSS via crafted Markdown

Risk 22
Severity
4.3
First published (updated )

pip/weblateWeblate: Private Translation Enumeration via Screenshot API

Risk 22
Severity
4.3
First published (updated )

pip/weblateWeblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_url

Risk 60
Severity
5.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/weblateWeblate's API Token Not Invalidated on Password Change

Risk 34
Severity
5.4
First published (updated )

pypi/weblateWeblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix Collision

Risk 26
Severity
5
First published (updated )

Weblate weblateWeblate: SSRF via the webhook add-on using unprotected fetch_url()

Risk 20
Severity
4.1
First published (updated )

Weblate weblateWeblate: Privilege escalation in the user API endpoint

Risk 79
Severity
8.8
First published (updated )

Weblate weblateWeblate: SSRF via Project-Level Machinery Configuration

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Weblate weblateWeblate: Arbitrary File Read via Symlink

Risk 44
Severity
7.7
First published (updated )

Weblate weblateWeblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploads

Risk 26
Severity
5
First published (updated )

Weblate weblateWeblate: Remote code execution during backup restoration

Risk 65
Severity
8.1
First published (updated )

Weblate weblateWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repository

Risk 38
Severity
6.8
First published (updated )

Weblate weblateWeblate has improper access control for the translation memory API

Risk 22
Severity
4.3
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Weblate weblateWeblate: Improper access control for pending tasks in API

Risk 17
Severity
3.1
First published (updated )

pip/weblateWeblate: Missing access control for the AddonViewSet API exposes all addon configurations

Risk 16
Severity
4.3
EPSS
0.03%
First published (updated )

pip/WeblateWeblate has an argument injection in management console

Risk 72
Severity
9.1
First published (updated )

pip/wlcwlc Path traversal: Unsanitized API slugs in download command

Risk 51
Severity
8.1
EPSS
0.03%
First published (updated )

Weblate weblateWeblate leaks information via screenshots

Risk 31
Severity
7.5
EPSS
0.04%
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

npm/wlcwlc may leak API keys due to an insecure API key configuration

Risk 24
Severity
5.5
EPSS
0.01%
First published (updated )

pip/wlcwlc can skip SSL verification

Risk 24
Severity
5.5
EPSS
0.01%
First published (updated )

Weblate weblateWeblate has git config file overwrite vulnerability that leads to remote code execution

Risk 72
Severity
9.1
First published (updated )

Weblate weblateWeblate has an arbitrary file read via symbolic links

Risk 44
Severity
7.7
First published (updated )

Weblate weblateWeblate has Server-Side Request Forgery vulnerability

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

pip/WeblateWeblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)

Risk 22
Severity
4.3
First published (updated )

pip/WeblateWeblate's over‑permissive webhook endpoint enables mass repository updates and component enumeration

Risk 27
Severity
5.3
First published (updated )

pip/WeblateWeblate has improper validation upon invitation acceptance

Risk 86
Severity
9.8
First published (updated )

pip/weblateWeblate leaks the IP of project members inviting users to assume reviewer roles in Audit log

Risk 19
Severity
3.5
First published (updated )

Weblate weblateWeblate integration with Anubis can lead to Open Redirect via redir parameter

Risk 38
Severity
6.1
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203