PatchSiren

WeblateOrg CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

LOW WeblateOrg CVE published 2026-08-26

CVE-2026-77573

CVE-2026-77573 is a server-side request forgery (SSRF) vulnerability in Weblate, a web-based continuous localization platform. An attacker with permission to manage component repository URLs can cause Weblate to reach internal VCS-compatible services, potentially exposing private repository contents. This issue is fixed in version 2026.8. Weblate validates the hostname's first DNS resolution, but external [truncated]

MEDIUM WeblateOrg CVE published 2026-08-26

CVE-2026-77507

CVE-2026-77507 debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T21:16:41.573Z and has not been modified since then. Weblate versions prior to 2026.8 have a vulnerability in object-scoped RSS feeds, which do not apply proper permission checks. This allows unauthorized users to read change-history metadata from private projects and restricted components. The exposed in [truncated]

MEDIUM WeblateOrg CVE published 2026-08-26

CVE-2026-62326

A vulnerability in Weblate, a web-based continuous localization platform, allows a user with the built-in 'Edit source' role to store a malicious regular expression in a source string's flags. This can be used to stall requests and deny service. The issue is fixed in version 2026.7. Affected Weblate instances, particularly those with untrusted users, are at risk of denial-of-service attacks. Defenders sho [truncated]

MEDIUM WeblateOrg CVE published 2026-08-26

CVE-2026-62249

CVE-2026-62249 is a vulnerability in Weblate, a web-based continuous localization platform. An authenticated user with access to a project can retrieve the change history of restricted components in that project through nested API change endpoints, even without permission to view those components directly. The issue allows unauthorized access to sensitive component change history, potentially exposing res [truncated]

HIGH WeblateOrg CVE published 2026-08-26

CVE-2026-61792

A project administrator in Weblate can read files outside their repository through the App store metadata download feature due to inadequate path confinement. This issue, fixed in version 2026.7, allows disclosure of file contents on the Weblate host outside the project's repository. The vulnerability is a result of incomplete path confinement, enabling an attacker-influenced path resolution. This issue i [truncated]

MEDIUM WeblateOrg CVE published 2026-08-26

CVE-2026-61790

CVE-2026-61790 is a medium-severity vulnerability in Weblate, a web-based continuous localization platform. The issue allows users to receive site-wide global permissions without configuring two-factor authentication (2FA), even if their team enforces 2FA for other permission levels. This discrepancy could lead to unintended access to sensitive areas, such as the site management interface. The vulnerabili [truncated]

HIGH WeblateOrg CVE published 2026-08-26

CVE-2026-55228

CVE-2026-55228 is a high-severity vulnerability in Weblate, a web-based continuous localization platform. In versions prior to 2026.7, the REST API did not properly enforce team scopes, allowing users to submit invalid team configurations and potentially expose private projects, permitting unauthorized translation, repository, and project-management operations.

MEDIUM WeblateOrg CVE published 2026-08-26

CVE-2026-55227

CVE-2026-55227 debrief based on the supplied source corpus. The CVE record was published on 2026-08-26T21:16:38.587Z. Weblate versions prior to 2026.7 have a vulnerability allowing unauthorized users to infer the existence of private project objects. The issue has been fixed in version 2026.7. Defenders should assess exposure and update to the latest version. This vulnerability has a CVSS score of 4.3 and [truncated]

LOW WeblateOrg CVE published 2026-08-26

CVE-2026-77508

CVE-2026-77508 is a low-severity vulnerability in Weblate, a web-based localization tool. An authenticated user can change their account's primary email address without verifying the new address, potentially allowing team invitations to be accepted by unintended recipients. This issue was fixed in version 2026.8. Weblate administrators should assess exposure and prioritize verification of their deployment [truncated]

MEDIUM WeblateOrg CVE published 2026-06-10

CVE-2026-50127

CVE-2026-50127 is a MEDIUM severity vulnerability in Weblate, a web-based localization tool. Versions from 5.15 to before 2026.6 are affected due to improper IP range restrictions. The `VCS_RESTRICT_PRIVATE` setting did not correctly account for certain IPv6 transitional ranges, multicast addresses, and semi-private IPv4 ranges. This oversight allowed some addresses to bypass private range restrictions. T [truncated]

MEDIUM WeblateOrg CVE published 2026-06-10

CVE-2026-45106

CVE-2026-45106 is a MEDIUM severity vulnerability in Weblate, a web-based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. This allows any contributor whose content reaches those fields to store HTML and CSS that runs inside the authenticated editor of every user who runs a matching search. The vulnerability has been patche [truncated]