PT-2026-1823 · Shiori · Shiori

CVE-2025-60538

·

Published

2026-01-09

·

Updated

2026-01-17

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions shiori versions 1.7.4 and below
Description A missing rate limit on the login page allows attackers to bypass authentication through brute-force attempts. The affected component is the login functionality, specifically the authentication process. The API endpoint involved is the login page. The vulnerability allows attackers to attempt multiple login requests without restriction, potentially guessing valid credentials.
Recommendations Apply rate limiting to the login page to restrict the number of login attempts within a specific timeframe.

Exploit

Fix

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-60538
GHSA-MW8H-G64C-RXV4
GO-2026-4308
SUSE-SU-2026:0142-1

Affected Products

Shiori