CVE-2026-33220

Weblate is a web based localization tool. In versions prior to 5.17, the translation memory API exposed unintended endpoints, which in turn didn't perform proper access control. This issue has been fixed in version 5.17. If developers are unable to update immediately, they can disable this feature as the CDN add-on is not enabled by default.
Configurations

Configuration 1 (hide)

cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-04-15 19:16

Updated : 2026-06-17 10:37


NVD link : CVE-2026-33220

Mitre link : CVE-2026-33220

CVE.ORG link : CVE-2026-33220


JSON object : View

Products Affected

weblate

  • weblate
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

CWE-200

Exposure of Sensitive Information to an Unauthorized Actor