Vulnerabilidades em WeblateOrg

47 resultados
Análise Vexday

Weblate registra 37 vulnerabilidades no histórico, com 1 classificada como crítica e 7 divulgadas nos últimos 90 dias, indicando desenvolvimento contínuo de correções. Nenhuma vulnerabilidade está sob ataque ativo conhecido (KEV=0), reduzindo o risco imediato. A fraqueza dominante é CWE-200 (exposição de informações sensíveis), sugerindo que problemas de privacidade e vazamento de dados foram os principais vetores de risco histórico.

CVE-2026-33435HIGHWeblate: Remote code execution during backup restorationEPSS 0.9%CVE-2025-68398CRITICALWeblate has git config file overwrite vulnerability that leads to remote code executionEPSS 0.8%CVE-2022-24710MEDIUMCross-site Scripting in WeblateEPSS 0.8%CVE-2026-61792HIGHWeblate path traversal allows a project administrator to read arbitrary files via App store metadata download (Incomplete Fix of CVE-2026-34242)EPSS 0.6%CVE-2026-34393HIGHWeblate: Privilege escalation in the user API endpointEPSS 0.5%CVE-2026-34242HIGHWeblate: Arbitrary File Read via SymlinkEPSS 0.5%CVE-2026-41654MEDIUMWeblate is Vulnerable to Authenticated SSRF via Project Backup Import bypassing validate_repo_urlEPSS 0.5%CVE-2026-24126MEDIUMWeblate has an argument injection in management consoleEPSS 0.5%CVE-2026-50127MEDIUMWeblate SSRF: outbound URL guard misses the NAT64 well-known prefix (64:ff9b::/96)EPSS 0.5%CVE-2026-55228HIGHWeblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorized read access to any private projectEPSS 0.4%CVE-2026-62326MEDIUMWeblate Has Uncontrolled Resource Consumption viaEPSS 0.4%CVE-2025-68279HIGHWeblate has an arbitrary file read via symbolic linksEPSS 0.4%CVE-2026-27457MEDIUMWeblate: Missing access control for the AddonViewSet API exposes all addon configurationsEPSS 0.4%CVE-2026-77507MEDIUMWeblate: Object-scoped RSS feeds disclose private change history to unauthorized usersEPSS 0.4%CVE-2026-61790MEDIUMWeblate: Team-enforced 2FA is bypassed for global permissionsEPSS 0.4%CVE-2026-23535HIGHwlc Path traversal: Unsanitized API slugs in download commandEPSS 0.4%CVE-2025-61587LOWWeblate integration with Anubis can lead to Open Redirect via redir parameterEPSS 0.4%CVE-2026-33220MEDIUMWeblate: JavaScript localization CDN add-on allows arbitrary local file read outside the repositoryEPSS 0.4%CVE-2026-21889LOWWeblate leaks information via screenshotsEPSS 0.4%CVE-2026-44263MEDIUMWeblate: Private Translation Enumeration via Screenshot APIEPSS 0.4%