PT-2026-38401 · Weblate · Weblate
Nijel
·
Published
2026-05-07
·
Updated
2026-06-01
·
CVE-2026-44264
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Weblate versions prior to 5.17.1
Description
The Markdown renderer used in user comments and other user-provided content fails to properly sanitize certain attributes, which could allow the injection of code into the HTML.
Recommendations
Update to version 5.17.1.
As a mitigation measure, ensure a strict Content Security Policy (CSP) is implemented to reduce the risks associated with HTML code injection.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Weblate