Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-3942
  • PyPI/weblate
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project 10 Sep
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-3941
  • PyPI/weblate
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups 10 Sep
  • Fix available
  • Severity - 4.3 (Medium)
GHSA-2q2q-jr9g-v9rf
  • PyPI/weblate
Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project 28 Aug
  • Fix available
  • Severity - 8.1 (High)
GHSA-2p9g-x3cv-5hh4
  • PyPI/weblate
Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups 28 Aug
  • Fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3416
  • PyPI/weblate
Weblate SSRF: outbound URL guard misses some private ranges 13 Jul
  • Fix available
  • Severity - 5.9 (Medium)
PYSEC-2026-3415
  • PyPI/weblate
Weblate: Stored HTML injection in editor search preview 13 Jul
  • Fix available
  • Severity - 4.6 (Medium)
GHSA-vmfc-9982-2m45
  • PyPI/weblate
Weblate SSRF: outbound URL guard misses some private ranges 07 Jul
  • Fix available
  • Severity - 5.9 (Medium)
PYSEC-2026-2037
  • PyPI/weblate
Weblate leaks information via screenshots 07 Jul
  • Fix available
  • Severity - 2.3 (Low)
PYSEC-2026-2040
  • PyPI/weblate
Weblate has an arbitrary file read via symbolic links 07 Jul
  • Fix available
  • Severity - 7.7 (High)
PYSEC-2026-2042
  • PyPI/weblate
Weblate has improper validation upon invitation acceptance 07 Jul
  • Fix available
  • Severity - 1.0 (Low)
PYSEC-2026-2036
  • PyPI/weblate
Weblate has a long session expiry when verifying second factor 07 Jul
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-2038
  • PyPI/weblate
Weblate exposes personal IP address via e-mail 07 Jul
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-2039
  • PyPI/weblate
Weblate lacks rate limiting when verifying second factor 07 Jul
  • Fix available
  • Severity - 4.9 (Medium)
PYSEC-2026-2041
  • PyPI/weblate
Weblate vulnerable to improper sanitization of project backups 07 Jul
  • Fix available
  • Severity - 2.1 (Low)
PYSEC-2026-571
  • PyPI/weblate
Weblate is vulnerable to RCE through Git config file overwrite 29 Jun
  • Fix available
  • Severity - 9.1 (Critical)
GHSA-hfpv-mc5v-p9mm
  • PyPI/weblate
Weblate has a Server-Side Request Forgery issue 26 May
  • Fix available
  • Severity - 5.0 (Medium)