{"schema_version":1,"title":"weblate (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 44 vulnerabilities in weblate (PyPI): 0 in the last 7 days and 17 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77573, was published on 26 August 2026.","url":"https://junglewise.ai/threats/technologies/weblate","json_url":"https://junglewise.ai/threats/technologies/weblate.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/weblate","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":6,"all_time":44,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":17,"last_365_days":40},"latest":[{"cve":"CVE-2026-77573","cvss":3.5,"epss":0.002,"slug":"cve-2026-77573-weblate-dns-rebinding-ssrf-in-vcs-operations","title":"Weblate DNS rebinding SSRF in VCS operations","severity":"low","exploited":false,"published_at":"2026-08-26T21:16:41.713+00:00","url":"https://junglewise.ai/threats/cve-2026-77573-weblate-dns-rebinding-ssrf-in-vcs-operations"},{"cve":"CVE-2026-77507","cvss":5.3,"epss":0.004,"slug":"cve-2026-77507-weblate-rss-feed-authorization-bypass","title":"Weblate RSS feed authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:41.573+00:00","url":"https://junglewise.ai/threats/cve-2026-77507-weblate-rss-feed-authorization-bypass"},{"cve":"CVE-2026-62326","cvss":6.5,"epss":0.0044,"slug":"cve-2026-62326-weblate-regex-denial-of-service-in-source-string-flags","title":"Weblate regex denial of service in source string flags","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:39.82+00:00","url":"https://junglewise.ai/threats/cve-2026-62326-weblate-regex-denial-of-service-in-source-string-flags"},{"cve":"CVE-2026-62249","cvss":4.3,"epss":0.0031,"slug":"cve-2026-62249-weblate-improper-authorization-in-nested-api-change-endpoints","title":"Weblate improper authorization in nested API change endpoints","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:39.667+00:00","url":"https://junglewise.ai/threats/cve-2026-62249-weblate-improper-authorization-in-nested-api-change-endpoints"},{"cve":"CVE-2026-61792","cvss":7.7,"epss":0.0059,"slug":"cve-2026-61792-weblate-path-traversal-in-app-store-metadata-download","title":"Weblate path traversal in App store metadata download","severity":"high","exploited":false,"published_at":"2026-08-26T21:16:39.51+00:00","url":"https://junglewise.ai/threats/cve-2026-61792-weblate-path-traversal-in-app-store-metadata-download"},{"cve":"CVE-2026-61790","cvss":4.4,"epss":0.004,"slug":"cve-2026-61790-weblate-team-enforced-2fa-bypass-for-global-permissions","title":"Weblate team-enforced 2FA bypass for global permissions","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:39.353+00:00","url":"https://junglewise.ai/threats/cve-2026-61790-weblate-team-enforced-2fa-bypass-for-global-permissions"},{"cve":"CVE-2026-55228","cvss":8.1,"epss":0.0045,"slug":"cve-2026-55228-weblate-idor-in-groupviewset-authorization-bypass","title":"Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did","severity":"high","exploited":false,"published_at":"2026-08-26T21:16:38.737+00:00","url":"https://junglewise.ai/threats/cve-2026-55228-weblate-idor-in-groupviewset-authorization-bypass"},{"cve":"CVE-2026-55227","cvss":4.3,"epss":0.0032,"slug":"cve-2026-55227-weblate-observable-object-existence-disclosure-via-http-status","title":"Weblate is a web-based localization tool. In versions prior to 2026.7, several endpoints look up objects in a globally scoped manner rather","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:38.587+00:00","url":"https://junglewise.ai/threats/cve-2026-55227-weblate-observable-object-existence-disclosure-via-http-status"},{"cve":"CVE-2026-77508","cvss":3.5,"epss":0.0026,"slug":"cve-2026-77508-weblate-unverified-email-change-in-rest-api","title":"Weblate unverified email change in REST API","severity":"low","exploited":false,"published_at":"2026-08-26T20:18:01.843+00:00","url":"https://junglewise.ai/threats/cve-2026-77508-weblate-unverified-email-change-in-rest-api"},{"cve":"CVE-2026-21889","cvss":4,"epss":0.0038,"slug":"cve-2026-21889-weblate-information-disclosure-via-unprotected-screenshots","title":"PYSEC-2026-2037 - Weblate leaks information via screenshots","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:18.828724+00:00","url":"https://junglewise.ai/threats/cve-2026-21889-weblate-information-disclosure-via-unprotected-screenshots"},{"cve":"CVE-2025-68279","cvss":3.1,"epss":0.0041,"slug":"cve-2025-68279-weblate-has-an-arbitrary-file-read-via-symbolic-links","title":"PYSEC-2026-2040 - Weblate has an arbitrary file read via symbolic links","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:13.529903+00:00","url":"https://junglewise.ai/threats/cve-2025-68279-weblate-has-an-arbitrary-file-read-via-symbolic-links"},{"cve":"CVE-2025-64725","cvss":4,"epss":0.0035,"slug":"cve-2025-64725-weblate-has-improper-validation-upon-invitation-acceptance","title":"PYSEC-2026-2042 - Weblate has improper validation upon invitation acceptance","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:12.872307+00:00","url":"https://junglewise.ai/threats/cve-2025-64725-weblate-has-improper-validation-upon-invitation-acceptance"},{"cve":"CVE-2025-58352","cvss":4,"epss":0.0029,"slug":"cve-2025-58352-weblate-weak-session-expiry-during-second-factor-verification","title":"PYSEC-2026-2036 - Weblate has a long session expiry when verifying second factor","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:03.211451+00:00","url":"https://junglewise.ai/threats/cve-2025-58352-weblate-weak-session-expiry-during-second-factor-verification"},{"cve":"CVE-2025-49134","cvss":3.1,"epss":0.0032,"slug":"cve-2025-49134-weblate-exposes-personal-ip-address-via-e-mail","title":"PYSEC-2026-2038 - Weblate exposes personal IP address via e-mail","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.301085+00:00","url":"https://junglewise.ai/threats/cve-2025-49134-weblate-exposes-personal-ip-address-via-e-mail"},{"cve":"CVE-2025-47951","cvss":3.1,"epss":0.0027,"slug":"cve-2025-47951-weblate-lacks-rate-limiting-when-verifying-second-factor","title":"PYSEC-2026-2039 - Weblate lacks rate limiting when verifying second factor","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:55.231866+00:00","url":"https://junglewise.ai/threats/cve-2025-47951-weblate-lacks-rate-limiting-when-verifying-second-factor"},{"cve":"CVE-2024-39303","cvss":3.1,"epss":0.0032,"slug":"cve-2024-39303-weblate-vulnerable-to-improper-sanitization-of-project-backups","title":"PYSEC-2026-2041 - Weblate vulnerable to improper sanitization of project backups","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:36.062688+00:00","url":"https://junglewise.ai/threats/cve-2024-39303-weblate-vulnerable-to-improper-sanitization-of-project-backups"},{"cve":"CVE-2025-68398","cvss":3.1,"epss":0.0079,"slug":"cve-2025-68398-weblate-is-vulnerable-to-rce-through-git-config-file-overwrite","title":"PYSEC-2026-571 - Weblate is vulnerable to RCE through Git config file overwrite","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:38.66267+00:00","url":"https://junglewise.ai/threats/cve-2025-68398-weblate-is-vulnerable-to-rce-through-git-config-file-overwrite"},{"cve":"CVE-2026-50127","cvss":5.9,"epss":0.0047,"slug":"cve-2026-50127-weblate-ssrf-via-private-range-restriction-bypass-in-vcs-restrict","title":"Weblate SSRF via private range restriction bypass in VCS_RESTRICT_PRIVATE","severity":"medium","exploited":false,"published_at":"2026-06-10T20:17:29.427+00:00","url":"https://junglewise.ai/threats/cve-2026-50127-weblate-ssrf-via-private-range-restriction-bypass-in-vcs-restrict"},{"cve":"CVE-2026-45106","cvss":4.6,"epss":0.0029,"slug":"cve-2026-45106-weblate-stored-xss-in-live-search-preview","title":"Weblate stored XSS in live search preview","severity":"medium","exploited":false,"published_at":"2026-06-10T20:17:27.22+00:00","url":"https://junglewise.ai/threats/cve-2026-45106-weblate-stored-xss-in-live-search-preview"},{"cve":"CVE-2025-66407","cvss":5,"epss":0.0024,"slug":"cve-2025-66407-weblate-ssrf-in-create-component-functionality","title":"Weblate SSRF in Create Component functionality","severity":"medium","exploited":false,"published_at":"2026-05-26T16:41:13+00:00","url":"https://junglewise.ai/threats/cve-2025-66407-weblate-ssrf-in-create-component-functionality"},{"cve":"CVE-2026-44264","cvss":4.3,"epss":0.0037,"slug":"cve-2026-44264-weblate-xss-in-markdown-renderer-via-image-attributes","title":"Weblate XSS in Markdown renderer via image attributes","severity":"medium","exploited":false,"published_at":"2026-05-07T15:16:10.76+00:00","url":"https://junglewise.ai/threats/cve-2026-44264-weblate-xss-in-markdown-renderer-via-image-attributes"},{"cve":"CVE-2026-44263","cvss":4.3,"epss":0.0038,"slug":"cve-2026-44263-weblate-translation-enumeration-via-api-information-disclosure","title":"Weblate translation enumeration via API information disclosure","severity":"medium","exploited":false,"published_at":"2026-05-07T15:16:10.613+00:00","url":"https://junglewise.ai/threats/cve-2026-44263-weblate-translation-enumeration-via-api-information-disclosure"},{"cve":"CVE-2026-41654","cvss":8.1,"epss":0.005,"slug":"cve-2026-41654-weblate-ssrf-via-crafted-project-backup-import","title":"Weblate SSRF via crafted project backup import","severity":"high","exploited":false,"published_at":"2026-05-07T15:16:07.907+00:00","url":"https://junglewise.ai/threats/cve-2026-41654-weblate-ssrf-via-crafted-project-backup-import"},{"cve":"CVE-2026-41519","cvss":4.2,"epss":0.0037,"slug":"cve-2026-41519-weblate-insufficient-session-expiration-for-api-tokens-on","title":"Weblate insufficient session expiration for API tokens on password change","severity":"medium","exploited":false,"published_at":"2026-05-07T15:16:07.16+00:00","url":"https://junglewise.ai/threats/cve-2026-41519-weblate-insufficient-session-expiration-for-api-tokens-on"},{"cve":"CVE-2026-40256","cvss":5,"epss":0.0037,"slug":"cve-2026-40256-weblate-path-traversal-via-repository-boundary-check-bypass","title":"Weblate path traversal via repository boundary check bypass","severity":"medium","exploited":false,"published_at":"2026-04-16T21:08:47+00:00","url":"https://junglewise.ai/threats/cve-2026-40256-weblate-path-traversal-via-repository-boundary-check-bypass"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":7},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":9},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"weblate (PyPI)","slug":"weblate","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://weblate.org/","repo_url":"https://github.com/WeblateOrg/weblate","description":"A web-based translation tool with tight version control integration.","url":"https://junglewise.ai/threats/technologies/weblate"},"most_severe":[{"cve":"CVE-2026-34393","cvss":8.8,"epss":0.0054,"slug":"cve-2026-34393-weblate-privilege-escalation-in-user-api-endpoint","title":"Weblate privilege escalation in user API endpoint","severity":"high","exploited":false,"published_at":"2026-04-16T20:43:48+00:00","url":"https://junglewise.ai/threats/cve-2026-34393-weblate-privilege-escalation-in-user-api-endpoint"},{"cve":"CVE-2026-41654","cvss":8.1,"epss":0.005,"slug":"cve-2026-41654-weblate-ssrf-via-crafted-project-backup-import","title":"Weblate SSRF via crafted project backup import","severity":"high","exploited":false,"published_at":"2026-05-07T15:16:07.907+00:00","url":"https://junglewise.ai/threats/cve-2026-41654-weblate-ssrf-via-crafted-project-backup-import"},{"cve":"CVE-2026-55228","cvss":8.1,"epss":0.0045,"slug":"cve-2026-55228-weblate-idor-in-groupviewset-authorization-bypass","title":"Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.7, the REST API did","severity":"high","exploited":false,"published_at":"2026-08-26T21:16:38.737+00:00","url":"https://junglewise.ai/threats/cve-2026-55228-weblate-idor-in-groupviewset-authorization-bypass"},{"cve":"CVE-2026-33435","cvss":8,"epss":0.0088,"slug":"cve-2026-33435-weblate-remote-code-execution-in-backup-restoration","title":"Weblate remote code execution in backup restoration","severity":"high","exploited":false,"published_at":"2026-04-16T20:41:38+00:00","url":"https://junglewise.ai/threats/cve-2026-33435-weblate-remote-code-execution-in-backup-restoration"},{"cve":"CVE-2026-61792","cvss":7.7,"epss":0.0059,"slug":"cve-2026-61792-weblate-path-traversal-in-app-store-metadata-download","title":"Weblate path traversal in App store metadata download","severity":"high","exploited":false,"published_at":"2026-08-26T21:16:39.51+00:00","url":"https://junglewise.ai/threats/cve-2026-61792-weblate-path-traversal-in-app-store-metadata-download"},{"cve":"CVE-2026-34242","cvss":7.7,"epss":0.0053,"slug":"cve-2026-34242-weblate-arbitrary-file-read-via-symlink-in-zip-download","title":"Weblate arbitrary file read via symlink in ZIP download","severity":"high","exploited":false,"published_at":"2026-04-16T20:43:11+00:00","url":"https://junglewise.ai/threats/cve-2026-34242-weblate-arbitrary-file-read-via-symlink-in-zip-download"},{"cve":"CVE-2026-33220","cvss":6.8,"epss":0.0039,"slug":"cve-2026-33220-weblate-path-traversal-in-javascript-localization-cdn-add-on","title":"Weblate path traversal in JavaScript localization CDN add-on","severity":"medium","exploited":false,"published_at":"2026-04-16T20:41:29+00:00","url":"https://junglewise.ai/threats/cve-2026-33220-weblate-path-traversal-in-javascript-localization-cdn-add-on"},{"cve":"CVE-2026-62326","cvss":6.5,"epss":0.0044,"slug":"cve-2026-62326-weblate-regex-denial-of-service-in-source-string-flags","title":"Weblate regex denial of service in source string flags","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:39.82+00:00","url":"https://junglewise.ai/threats/cve-2026-62326-weblate-regex-denial-of-service-in-source-string-flags"},{"cve":"CVE-2026-50127","cvss":5.9,"epss":0.0047,"slug":"cve-2026-50127-weblate-ssrf-via-private-range-restriction-bypass-in-vcs-restrict","title":"Weblate SSRF via private range restriction bypass in VCS_RESTRICT_PRIVATE","severity":"medium","exploited":false,"published_at":"2026-06-10T20:17:29.427+00:00","url":"https://junglewise.ai/threats/cve-2026-50127-weblate-ssrf-via-private-range-restriction-bypass-in-vcs-restrict"},{"cve":"CVE-2026-77507","cvss":5.3,"epss":0.004,"slug":"cve-2026-77507-weblate-rss-feed-authorization-bypass","title":"Weblate RSS feed authorization bypass","severity":"medium","exploited":false,"published_at":"2026-08-26T21:16:41.573+00:00","url":"https://junglewise.ai/threats/cve-2026-77507-weblate-rss-feed-authorization-bypass"}],"generated_at":"2026-09-27T03:07:00.185062+00:00"}