← Back

CVE-2025-47951

nvd nist
Published: Jun 16, 2025Modified: Jul 16, 2025

JSON object

Loading...
4.9
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Exploitability: 1.8 / Impact: 2.7
Source: security-advisories@github.com (Secondary)

Description

Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.

Affected (1)

Products: Weblate: Weblate
1 product
Weblate
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 5.12

References (5)

Source: security-advisories@github.com
Issue Tracking
Source: security-advisories@github.com
Release Notes
Source: security-advisories@github.com
Vendor Advisory
Source: security-advisories@github.com
Permissions Required

Timeline

No history available yet.