Security: WeblateOrg/wlc
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
print_html outputs API data without HTML escaping, enabling stored XSSGHSA-gx2m-mcc2-r4p3 published
Apr 21, 2026 by nijelModerate -
Path traversal: Unsanitized API slugs in download commandGHSA-mmwx-79f6-67jg published
Jan 16, 2026 by nijelHigh -
Insecure API key configurationGHSA-9rp8-h4g8-8766 published
Jan 12, 2026 by nijelModerate -
SSL verification skipGHSA-2mmv-7rrp-g8xh published
Jan 12, 2026 by nijelLow