๐Ÿ” CVE Alert

CVE-2026-45106

MEDIUM 4.6

Weblate: Stored HTML injection in editor search preview

CVSS Score
4.6
EPSS Score
0.0%
EPSS Percentile
0th

Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search. This issue has been patched in version 2026.5.

CWE CWE-79
Vendor weblateorg
Product weblate
Published Jun 10, 2026
Stay Ahead of the Next One

Get instant alerts for weblateorg weblate

Be the first to know when new medium vulnerabilities affecting weblateorg weblate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

WeblateOrg / weblate
< 2026.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-6wxc-8mgq-w26m github.com: https://github.com/WeblateOrg/weblate/pull/19422 github.com: https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.5