Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
History

Tue, 17 Jun 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 16 Jun 2025 21:15:00 +0000

Type Values Removed Values Added
Description Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
Title Weblate lacks rate limiting when verifying second factor
Weaknesses CWE-307
References
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-06-16T20:57:52.509Z

Updated: 2025-06-17T18:52:13.582Z

Reserved: 2025-05-14T10:32:43.531Z

Link: CVE-2025-47951

cve-icon Vulnrichment

Updated: 2025-06-17T18:52:08.109Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-16T21:15:24.010

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-47951

cve-icon Redhat

No data.