CVE-2026-44264
MEDIUM EPSS 19.2%
Published May 7, 20261mo ago · Modified Jun 17, 20262w ago
4.3 CVSS 3.1
Published May 7, 2026 1mo ago
Last Modified Jun 17, 2026 2w ago
Description
Weblate is a web based localization tool. Prior to version 5.17.1, the Markdown renderer used in user comments and other user-provided content didn't properly sanitize some attributes. This issue has been patched in version 5.17.1.
CVSS Details
Base Score
Exploitability
Impact
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality None
Integrity Low
Availability None
Threat Intelligence
EPSS Exploit Probability
19.2% percentile
Exploit & Patch Status
No Known Exploit
Patch Available
Weaknesses 1
CWE-80
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| weblate | weblate | * | <5.17.1 |
References 4
- github.com https://github.com/WeblateOrg/weblate/commit/85abc9df88b7464f4c0e794aef752e45f4230f75
- github.com https://github.com/WeblateOrg/weblate/pull/19259
- github.com https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.17.1
- github.com https://github.com/WeblateOrg/weblate/security/advisories/GHSA-5cmv-3rc4-7279
Remediation
- github.com https://github.com/WeblateOrg/weblate/commit/85abc9df88b7464f4c0e794aef752e45f4230f75
- github.com https://github.com/WeblateOrg/weblate/pull/19259
- github.com https://github.com/WeblateOrg/weblate/security/advisories/GHSA-5cmv-3rc4-7279