PT-2025-51350 · Weblate · Weblate

Naxus-Audit

·

Published

2025-12-15

·

Updated

2026-01-21

·

CVE-2025-67715

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Weblate versions prior to 5.15
Description Weblate, a web-based localization tool, had a broken authorization issue in its REST API that allowed for systematic user and project enumeration. Specifically, it was possible to retrieve user notification settings or list all users via the API.
Recommendations Update to version 5.15 or later.

Exploit

Fix

Improper Access Control

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2025-67715
GHSA-3PMH-24WP-XPF4
PYSEC-2025-233

Affected Products

Weblate