Technology · PyPI
weblate (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 34 vulnerabilities in weblate (PyPI): 0 in the last 7 days and 9 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77573, was published on 26 August 2026.
- Last 7 days
- 0
- Last 90 days
- 9
- Critical, all time
- 0
- Exploited in the wild
- 0
About weblate (PyPI)
A web-based translation tool with tight version control integration.
Latest weblate (PyPI) vulnerabilities
- CVE-2026-77573: Weblate DNS rebinding SSRF in VCS operationslowCVSS 3.5EPSS 0.2%
- CVE-2026-77507: Weblate RSS feed authorization bypassmediumCVSS 5.3EPSS 0.4%
- CVE-2026-62326: Weblate regex denial of service in source string flagsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-62249: Weblate improper authorization in nested API change endpointsmediumCVSS 4.3EPSS 0.3%
- CVE-2026-61792: Weblate path traversal in App store metadata downloadhighCVSS 7.7EPSS 0.6%
- CVE-2026-61790: Weblate team-enforced 2FA bypass for global permissionsmediumCVSS 4.4EPSS 0.4%
- CVE-2026-55228: Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7…highCVSS 8.1EPSS 0.4%
- CVE-2026-55227: Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally…mediumCVSS 4.3EPSS 0.3%
- CVE-2026-77508: Weblate unverified email change in REST APIlowCVSS 3.5EPSS 0.3%
- CVE-2026-50127: Weblate SSRF via private range restriction bypass in VCS_RESTRICT_PRIVATEmediumCVSS 5.9EPSS 0.5%
- CVE-2026-45106: Weblate stored XSS in live search previewmediumCVSS 4.6EPSS 0.3%
- CVE-2025-66407: Weblate SSRF in Create Component functionalitymediumCVSS 5EPSS 0.2%
- CVE-2026-44264: Weblate XSS in Markdown renderer via image attributesmediumCVSS 4.3EPSS 0.4%
- CVE-2026-44263: Weblate translation enumeration via API information disclosuremediumCVSS 4.3EPSS 0.4%
- CVE-2026-41654: Weblate SSRF via crafted project backup importhighCVSS 8.1EPSS 0.5%
- CVE-2026-41519: Weblate insufficient session expiration for API tokens on password changemediumCVSS 4.2EPSS 0.4%
- CVE-2026-40256: Weblate path traversal via repository boundary check bypassmediumCVSS 5EPSS 0.4%
- CVE-2026-39845: Weblate SSRF in webhook add-on via fetch_urlmediumCVSS 4.1EPSS 0.3%
- CVE-2026-34393: Weblate privilege escalation in user API endpointhighCVSS 8.8EPSS 0.5%
- CVE-2026-34244: Weblate SSRF in Project-Level Machinery ConfigurationmediumCVSS 5EPSS 0.3%
- CVE-2026-34242: Weblate arbitrary file read via symlink in ZIP downloadhighCVSS 7.7EPSS 0.5%
- CVE-2026-33440: Weblate SSRF via redirect bypass in screenshot URL uploadsmediumCVSS 5EPSS 0.3%
- CVE-2026-33435: Weblate remote code execution in backup restorationhighCVSS 8EPSS 0.9%
- CVE-2026-33220: Weblate path traversal in JavaScript localization CDN add-onmediumCVSS 6.8EPSS 0.4%
- CVE-2026-33214: Weblate improper access control in translation memory APImediumCVSS 4.3EPSS 0.3%
Most severe weblate (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-34393: Weblate privilege escalation in user API endpointhighCVSS 8.8EPSS 0.5%
- CVE-2026-41654: Weblate SSRF via crafted project backup importhighCVSS 8.1EPSS 0.5%
- CVE-2026-55228: Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7…highCVSS 8.1EPSS 0.4%
- CVE-2026-33435: Weblate remote code execution in backup restorationhighCVSS 8EPSS 0.9%
- CVE-2026-61792: Weblate path traversal in App store metadata downloadhighCVSS 7.7EPSS 0.6%
- CVE-2026-34242: Weblate arbitrary file read via symlink in ZIP downloadhighCVSS 7.7EPSS 0.5%
- CVE-2026-33220: Weblate path traversal in JavaScript localization CDN add-onmediumCVSS 6.8EPSS 0.4%
- CVE-2026-62326: Weblate regex denial of service in source string flagsmediumCVSS 6.5EPSS 0.4%
- CVE-2026-50127: Weblate SSRF via private range restriction bypass in VCS_RESTRICT_PRIVATEmediumCVSS 5.9EPSS 0.5%
- CVE-2026-77507: Weblate RSS feed authorization bypassmediumCVSS 5.3EPSS 0.4%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 9 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/weblate.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "weblate (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/weblate, 26 September 2026.