Vulnerabilidades em WeblateOrg
47 resultadosAnálise Vexday
Weblate registra 37 vulnerabilidades no histórico, com 1 classificada como crítica e 7 divulgadas nos últimos 90 dias, indicando desenvolvimento contínuo de correções. Nenhuma vulnerabilidade está sob ataque ativo conhecido (KEV=0), reduzindo o risco imediato. A fraqueza dominante é CWE-200 (exposição de informações sensíveis), sugerindo que problemas de privacidade e vazamento de dados foram os principais vetores de risco histórico.
CVE-2025-32021LOWWeblate VCS credentials included in URL parameters are potentially logged and saved into browser history as plaintextEPSS 0.4%CVE-2026-40256MEDIUMWeblate: Prefix-Based Repository Boundary Check Bypass via Symlink/Junction Path Prefix CollisionEPSS 0.4%CVE-2026-41519MEDIUMWeblate's API Token Not Invalidated on Password ChangeEPSS 0.4%CVE-2026-44264MEDIUMWeblate is vulnerable to XSS via crafted MarkdownEPSS 0.4%CVE-2025-64725LOWWeblate has improper validation upon invitation acceptanceEPSS 0.3%CVE-2026-39845MEDIUMWeblate: SSRF via the webhook add-on using unprotected fetch_url()EPSS 0.3%CVE-2026-34244MEDIUMWeblate: SSRF via Project-Level Machinery ConfigurationEPSS 0.3%CVE-2026-55227MEDIUMObservable object existence disclosure in private Weblate projects via globally scoped object lookupsEPSS 0.3%CVE-2025-49134LOWWeblate exposes personal IP address via e-mailEPSS 0.3%CVE-2024-39303MEDIUMWeblate vulnerabler to improper sanitization of project backupsEPSS 0.3%CVE-2026-33440MEDIUMWeblate: Authenticated SSRF via redirect bypass of ALLOWED_ASSET_DOMAINS in screenshot URL uploadsEPSS 0.3%CVE-2026-62249MEDIUMWeblate: Restricted-component change history leaked to non-member project users through the nested `GET /api/projects/{slug}/changes/` endpointEPSS 0.3%CVE-2026-42150MEDIUMwlc: print_html outputs API data without HTML escaping, enabling stored XSSEPSS 0.3%CVE-2026-33214MEDIUMWeblate has improper access control for the translation memory APIEPSS 0.3%CVE-2025-58352LOWWeblate has long session expiry times during second factor verificationEPSS 0.3%CVE-2026-45106MEDIUMWeblate: Stored HTML injection in editor search previewEPSS 0.3%CVE-2025-67715MEDIUMWeblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)EPSS 0.3%CVE-2025-47951MEDIUMWeblate lacks rate limiting when verifying second factorEPSS 0.3%CVE-2026-33212LOWWeblate: Improper access control for pending tasks in APIEPSS 0.3%CVE-2026-77508LOWWeblate: Unverified REST API email changesEPSS 0.3%