Weblate is a web-based translation management and collaboration platform that enables localization workflows across open-source and enterprise projects; its relatively narrow but strategically positioned product line attracts a persistent stream of disclosures. The vendor's vulnerability profile is shaped by its role as a centralized repository of source strings, translation data, and user credentials, with recurring weaknesses spanning sensitive-information exposure, path-traversal flaws, server-side request forgery, and access-control lapses that reflect the challenges of secure multi-tenant web application design. A meaningful share of these vulnerabilities reach serious severity, and the exposure concentrates within the Weblate platform itself and its command-line tooling. Defenders deploying Weblate for organizational localization should monitor this vendor's releases closely and treat internet-facing instances as a patching priority given the sensitivity of the data the platform handles; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Weblate over time
Signals from CVEs in this vendor scope (37 CVEs).
37 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24126CRITICAL Weblate is a web based localization tool. Prior to 5.16.0, the SSH management console did not validate the passed input while adding the SSH host key, which could lead to an argume | Feb 19, 2026 | 9.1 | 32 | NO | NO |
CVE-2025-68398CRITICAL Weblate is a web based localization tool. In versions prior to 5.15.1, it was possible to overwrite Git configuration remotely and override some of its behavior. Version 5.15.1 fix | Dec 18, 2025 | 9.1 | 31 | NO | NO |
CVE-2026-41654HIGH Weblate is a web based localization tool. Prior to version 5.17.1, an authenticated user with project.add permission (default on hosted Weblate SaaS and for any user holding an act | May 7, 2026 | 8.1 | 30 | NO | NO |
CVE-2026-23535HIGH wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted ser | Jan 16, 2026 | 8.0 | 30 | NO | NO |
CVE-2025-64725CRITICAL Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workar | Dec 15, 2025 | 9.8 | 29 | NO | NO |
CVE-2022-23915HIGH The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can | Mar 4, 2022 | 8.8 | 29 | NO | NO |
CVE-2026-34393HIGH Weblate is a web based localization tool. In versions prior to 5.17, the user patching API endpoint didn't properly limit the scope of edits. This issue has been fixed in version 5 | Apr 15, 2026 | 8.8 | 28 | NO | NO |
CVE-2026-21889HIGH Weblate is a web based localization tool. Prior to 5.15.2, the screenshot images were served directly by the HTTP server without proper access control. This could allow an unauthen | Jan 14, 2026 | 7.5 | 28 | NO | NO |
CVE-2026-33435HIGH Weblate is a web based localization tool. In versions prior to 5.17, the project backup didn't filter Git and Mercurial configuration files which could lead to remote code executio | Apr 15, 2026 | 8.0 | 27 | NO | NO |
CVE-2026-34242HIGH Weblate is a web based localization tool. In versions prior to 5.17, the ZIP download feature didn't verify downloaded files, potentially following symlinks outside the repository | Apr 15, 2026 | 7.7 | 26 | NO | NO |
Signals from CVEs in this vendor scope (37 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Weblate.
Media articles that mention a CVE ID that affects a product developed by Weblate — matched by CVE ID, not by vendor name.