Weblate 是一个基于 Web 的本地化工具。在 2026.7 之前的版本中,某些端点在查询对象时采用了全局作用域的方式,而没有将查询范围限制在用户可访问的项目内。因此,当用户请求其无权查看的对象时,系统会返回 HTTP 403(禁止访问),而不是 404(未找到)。这种差异使得未授权的用户能够推断出某个对象是否存在于私有的 Weblate 项目中。该问题已在 2026.7 版本中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| WeblateOrg | weblate | < 2026.7 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-55228 | 8.1 HIGH | Weblate:: WebIDOR in GroupViewSet allows authenticated project manager to gain unauthorize |
| CVE-2026-61792 | 7.7 HIGH | Weblate path traversal allows a project administrator to read arbitrary files via App stor |
| CVE-2026-62326 | 6.5 MEDIUM | Weblate Has Uncontrolled Resource Consumption via |
| CVE-2026-77507 | 5.3 MEDIUM | Weblate: Object-scoped RSS feeds disclose private change history to unauthorized users |
| CVE-2026-61790 | 4.4 MEDIUM | Weblate: Team-enforced 2FA is bypassed for global permissions |
| CVE-2026-62249 | 4.3 MEDIUM | Weblate: Restricted-component change history leaked to non-member project users through th |
| CVE-2026-77508 | 3.5 LOW | Weblate: Unverified REST API email changes |
| CVE-2026-77573 | 3.5 LOW | Weblate: DNS rebinding in VCS operations allows server-side request forgery |
No comments yet