Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
Metrics
Affected Vendors & Products
References
History
Tue, 17 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 16 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12. | |
Title | Weblate lacks rate limiting when verifying second factor | |
Weaknesses | CWE-307 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-16T20:57:52.509Z
Updated: 2025-06-17T18:52:13.582Z
Reserved: 2025-05-14T10:32:43.531Z
Link: CVE-2025-47951

Updated: 2025-06-17T18:52:08.109Z

Status : Awaiting Analysis
Published: 2025-06-16T21:15:24.010
Modified: 2025-06-17T20:50:23.507
Link: CVE-2025-47951

No data.