PT-2026-1823 · Shiori · Shiori

Published

2026-01-09

·

Updated

2026-01-17

·

CVE-2025-60538

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions shiori versions 1.7.4 and below
Description A missing rate limit on the login page allows attackers to bypass authentication through brute-force attempts. The affected component is the login functionality, specifically the authentication process. The API endpoint involved is the login page. The vulnerability allows attackers to attempt multiple login requests without restriction, potentially guessing valid credentials.
Recommendations Apply rate limiting to the login page to restrict the number of login attempts within a specific timeframe.

Fix

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

CVE-2025-60538
GHSA-MW8H-G64C-RXV4
GO-2026-4308
SUSE-SU-2026:0142-1

Affected Products

Shiori