CVE-2026-42150Disclosure(weblate / wlc)

LOWCVSS 4.8 · MEDIUM

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escaping, allowing cross-site scripting when the output is rendered in a browser. This issue has been patched in version 2.0.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wlc

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked at 2 mentions on most recent observed day (2026-05-09)
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wlc

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-05-08: 1Mentions · 2026-05-09: 2Technical Details · 2026-05-08: 1Technical Details · 2026-05-09: 205-0805-09
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-05-081
Disclosure1
2026-05-092
Disclosure1General1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    General

    🚨*CVE* CVE-2026-42150 wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escapi… https://www.cve.org/CVERecord?id=CVE-2026-42150 ----- Traducción: CVE-2026-42150 wlc… http://infoflow.cloud`

    Post summary

    The text outlines technical details of CVE-2026-42150—a lack of HTML escaping in Weblate’s wlc client—without indicating exploitation, mitigation, or a PoC.

    0000033
    76 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42150 wlc is a Weblate command-line client using Weblate's REST API. Prior to version 2.0.0, the HTML output format in wlc embeds API response data into HTML without escapi… https://www.cve.org/CVERecord?id=CVE-2026-42150

    Post summary

    The tweet announces CVE‑2026‑42150 affecting Weblate’s command‑line client, noting that earlier versions embed unescaped API responses in HTML, but does not provide proof of exploitation, PoC, or patch details.

    00000272
    57.5K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-42150 📊 Severity: 5.1 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-42150 #CVE-2026-42150 #CVE #Medium #CyberSecurity #InfoSec https://t.co/ggsfV2i4qE

    Post summary

    The tweet serves to alert about CVE-2026-42150, citing its medium severity and linking to the NVD entry, but offers no additional technical or exploitation information.

    0000036
    157 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appweblatewlc---

Explore more