Loading
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
Cite this page
CVE-2025-49134. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2025-49134
Use CWE-359, Weblate vendor hub and Weblate product page to widen CVE-2025-49134 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2026-34393, CVE-2026-33435 and CVE-2026-34242 for nearby disclosures in the same product family.