Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/weblate

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-41654 is a medium severity vulnerability in Weblate versions prior to 5.17.1. It allows an authenticated user with project.add permission to import a crafted project backup ZIP containing a component JSON with a malicious repository URL. This URL can point to private network addresses or use disallowed schemes, bypassing input validation due to the use of bulk_create which skips Django's full_clean validation. The malicious URL is then written directly into the . git/config file. This issue has been fixed in Weblate version 5.17.

Join the discussion

Weblate is a web based localization tool. In versions prior to 5.17, a user with the project.edit permission (granted by the per-project "Administration" role) can configure machine translation service URLs pointing to arbitrary internal network addresses. During configuration validation, Weblate makes an HTTP request to the attacker-controlled URL and reflects up to 200 characters of the response body back to the user in an error message. This constitutes a Server-Side Request Forgery (SSRF) with partial response read. This issue has been fixed in version 5.17. If developers are unable to immediately upgrade, they can limit available machinery services via WEBLATE_MACHINERY setting.

Join the discussion

CVE-2026-33220 is a medium severity vulnerability in Weblate versions prior to 5.17 involving improper limitation of a pathname to a restricted directory (path traversal) in the translation memory API. This flaw allowed access to unintended endpoints without proper access control. The issue has been fixed in Weblate version 5.17. Users unable to upgrade immediately can mitigate risk by disabling the translation memory API feature, which is not enabled by default unless the CDN add-on is used.

Join the discussion

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.

Join the discussion

Weblate is a web based localization tool. In versions 5.14 and below, Weblate leaks the IP address of the project member inviting the user to the project in the audit log. The audit log includes IP addresses from admin-triggered actions, which can be viewed by invited users. This issue is fixed in version 5.14.1.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:pypi/weblate
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses