← Back

Wlc

wlc

Vendor: Weblate • 4 CVEs

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Weblate
1Wlc
Jun 17, 2026
May 8, 2026
N/A· v4
4.8 MEDIUM· v3
N/A· v2
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is r...Show more
wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser. This issue has been patched in version 2.0.0.Show less
1Weblate
1Wlc
Jun 17, 2026
Jan 16, 2026
N/A· v4
8.0 HIGH· v3
N/A· v2
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17...Show more
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.2, the multi-translation download could write to an arbitrary location when instructed by a crafted server. This vulnerability is fixed in 1.17.2.Show less
1Weblate
1Wlc
Jun 17, 2026
Jan 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This migh...Show more
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, wlc supported providing unscoped API keys in the setting. This practice was discouraged for years, but the code was never removed. This might cause the API key to be leaked to different servers.Show less
1Weblate
1Wlc
Jun 17, 2026
Jan 12, 2026
N/A· v4
5.5 MEDIUM· v3
N/A· v2
wlc is a Weblate command-line client using Weblate's REST API. Prior to 1.17.0, the SSL verification would be skipped for some crafted URLs. This vulnerability is fixed in 1.17.0.