PT-2025-25574 · Weblate · Weblate

Obscuredeer

·

Published

2025-06-16

·

Updated

2025-07-16

·

CVE-2025-47951

CVSS v3.1

4.9

Medium

VectorAV:N/AC:H/PR:L/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.12
Description The verification of the second factor was not subject to rate limiting, allowing an attacker with valid credentials to automate OTP guessing via the second factor endpoint.
Recommendations For versions prior to 5.12, update to version 5.12 to resolve the issue. As a temporary workaround, consider restricting access to the second factor endpoint to minimize the risk of exploitation.

Exploit

Fix

Improper Restriction of Excessive Authentication Attempts

Weakness Enumeration

Related Identifiers

CVE-2025-47951
GHSA-57JG-M997-CX3Q

Affected Products

Weblate