Vulnerabilities in WeblateOrg
46 resultsVexday analysis
Weblate registra 37 vulnerabilidades no histórico, com 1 classificada como crítica e 7 divulgadas nos últimos 90 dias, indicando desenvolvimento contínuo de correções. Nenhuma vulnerabilidade está sob ataque ativo conhecido (KEV=0), reduzindo o risco imediato. A fraqueza dominante é CWE-200 (exposição de informações sensíveis), sugerindo que problemas de privacidade e vazamento de dados foram os principais vetores de risco histórico.
CVE-2026-44263MEDIUMWeblate: Private Translation Enumeration via Screenshot APIEPSS 0.3%CVE-2025-58352LOWWeblate has long session expiry times during second factor verificationEPSS 0.3%CVE-2026-44264MEDIUMWeblate is vulnerable to XSS via crafted MarkdownEPSS 0.3%CVE-2026-39845MEDIUMWeblate: SSRF via the webhook add-on using unprotected fetch_url()EPSS 0.3%CVE-2025-67715MEDIUMWeblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)EPSS 0.3%CVE-2026-41519MEDIUMWeblate's API Token Not Invalidated on Password ChangeEPSS 0.3%CVE-2025-47951MEDIUMWeblate lacks rate limiting when verifying second factorEPSS 0.3%CVE-2026-55228HIGHWeblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private projectEPSS 0.3%CVE-2025-67492MEDIUMWeblate's over‑permissive webhook endpoint enables mass repository updates and component enumerationEPSS 0.3%CVE-2026-34244MEDIUMWeblate: SSRF via Project-Level Machinery ConfigurationEPSS 0.3%CVE-2026-61790MEDIUMWeblate: Team-enforced 2FA is bypassed for global permissionsEPSS 0.3%CVE-2026-62326MEDIUMWeblate Has Uncontrolled Resource Consumption viaEPSS 0.2%CVE-2025-66407MEDIUMWeblate has Server-Side Request Forgery vulnerabilityEPSS 0.2%CVE-2026-33440MEDIUMWeblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsEPSS 0.2%CVE-2026-77507MEDIUMWeblate: Object-scoped RSS feeds disclose private change history to unauthorized usersEPSS 0.2%CVE-2026-33214MEDIUMWeblate has improper access control for the translation memory APIEPSS 0.2%CVE-2026-33212LOWWeblate: Improper access control for pending tasks in APIEPSS 0.2%CVE-2026-45106MEDIUMWeblate: Stored HTML injection in editor search previewEPSS 0.2%CVE-2026-55227MEDIUMObservable object existence disclosure in private Weblate projects via globally scoped object lookupsEPSS 0.2%CVE-2026-22251MEDIUMwlc may leak API keys due to an insecure API key configurationEPSS 0.2%