id: PYSEC-2026-3415 published: "2026-07-13T15:19:08.568413Z" modified: "2026-07-13T16:07:30.857579Z" aliases: - CVE-2026-45106 - GHSA-6wxc-8mgq-w26m summary: "Weblate: Stored HTML injection in editor search preview" details: "### Impact\nWeblate's live search preview renders unit `source` and `context` as HTML without escaping. Any contributor whose content reaches those fields stores HTML and CSS that runs inside the authenticated editor of every user who runs a matching search.\n\n### Patches\n* https://github.com/WeblateOrg/weblate/pull/19422\n\n### Workarounds\nOnly the search preview on the selected views is affected.\n\n### Resources\nWeblate thanks @adrgs for reporting this issue responsibly via GitHub." affected: - package: name: weblate ecosystem: PyPI purl: pkg:pypi/weblate ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: "2026.5" versions: - "1.9" - "2.0" - "2.1" - "2.10" - 2.10.1 - "2.11" - "2.12" - "2.13" - 2.13.1 - "2.14" - 2.14.1 - "2.15" - "2.16" - "2.17" - 2.17.1 - "2.18" - "2.19" - 2.19.1 - "2.2" - "2.20" - "2.3" - "2.4" - "2.5" - "2.6" - "2.7" - "2.8" - "2.9" - "3.0" - 3.0.1 - "3.1" - 3.1.1 - "3.10" - 3.10.1 - 3.10.2 - 3.10.3 - "3.11" - 3.11.1 - 3.11.2 - 3.11.3 - "3.2" - 3.2.1 - 3.2.2 - "3.3" - "3.4" - "3.5" - 3.5.1 - "3.6" - 3.6.1 - "3.7" - 3.7.1 - "3.8" - "3.9" - 3.9.1 - "4.0" - 4.0.1 - 4.0.2 - 4.0.3 - 4.0.4 - "4.1" - 4.1.1 - "4.10" - 4.10.1 - "4.11" - 4.11.1 - 4.11.2 - "4.12" - 4.12.1 - 4.12.2 - "4.13" - 4.13.1 - "4.14" - 4.14.1 - 4.14.2 - "4.15" - 4.15.1 - 4.15.2 - "4.16" - 4.16.1 - 4.16.2 - 4.16.3 - 4.16.4 - "4.17" - "4.18" - 4.18.1 - 4.18.2 - "4.2" - 4.2.1 - 4.2.2 - "4.3" - 4.3.1 - 4.3.2 - "4.4" - 4.4.1 - 4.4.2 - "4.5" - 4.5.1 - 4.5.2 - 4.5.3 - "4.6" - 4.6.1 - 4.6.2 - "4.7" - 4.7.1 - 4.7.2 - "4.8" - 4.8.1 - "4.9" - 4.9.1 - "5.0" - 5.0.1 - 5.0.2 - "5.1" - 5.1.1 - "5.10" - 5.10.1 - 5.10.2 - 5.10.3 - 5.10.4 - "5.11" - 5.11.1 - 5.11.3 - 5.11.4 - 5.12.1 - 5.12.2 - "5.13" - 5.13.1 - 5.13.2 - 5.13.3 - "5.14" - 5.14.1 - 5.14.2 - 5.14.3 - "5.15" - 5.15.1 - 5.15.2 - "5.16" - 5.16.1 - 5.16.2 - "5.17" - 5.17.1 - "5.2" - 5.2.1 - "5.3" - 5.3.1 - "5.4" - 5.4.1 - 5.4.2 - 5.4.3 - "5.5" - 5.5.2 - 5.5.3 - 5.5.4 - 5.5.5 - "5.6" - 5.6.1 - 5.6.2 - "5.7" - 5.7.1 - 5.7.2 - 5.8.1 - 5.8.2 - 5.8.3 - 5.8.4 - 5.9.1 - 5.9.2 references: - type: WEB url: https://github.com/WeblateOrg/weblate/security/advisories/GHSA-6wxc-8mgq-w26m - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2026-45106 - type: WEB url: https://github.com/WeblateOrg/weblate/pull/19422 - type: WEB url: https://github.com/WeblateOrg/weblate/commit/8b0adf1d0b43dfc0d09da4b878857b2288b84f2d - type: PACKAGE url: https://github.com/WeblateOrg/weblate - type: WEB url: https://github.com/WeblateOrg/weblate/releases/tag/weblate-2026.5 - type: PACKAGE url: https://pypi.org/project/weblate - type: ADVISORY url: https://github.com/advisories/GHSA-6wxc-8mgq-w26m severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:N