Loading
The package weblate from 0 and before 4.11.1 are vulnerable to Remote Code Execution (RCE) via argument injection when using git or mercurial repositories. Authenticated users, can change the behavior of the application in an unintended way, leading to command execution.
Cite this page
CVE-2022-23915. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2022-23915
Use CWE-88, Weblate vendor hub and Weblate product page to widen CVE-2022-23915 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34393, CVE-2026-33435 and CVE-2026-34242 for nearby disclosures in the same product family.