CVE 4.3 MEDIUM

Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)_CVE-2025-67715

4.3 / 10
MEDIUM
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.

Basic Information

ID CVE-2025-67715
Source GitHub_M
Published Dec 16, 2025 at 00:07

Affected Product

Vendor WeblateOrg
Product weblate
Version < 5.15
Affected Versions WeblateOrg weblate < 5.15

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.