Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weblate
Weblate weblate |
|
| CPEs | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Weblate
Weblate weblate |
Tue, 17 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12. | |
| Title | Weblate lacks rate limiting when verifying second factor | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-16T20:57:52.509Z
Updated: 2025-06-17T18:52:13.582Z
Reserved: 2025-05-14T10:32:43.531Z
Link: CVE-2025-47951
Updated: 2025-06-17T18:52:08.109Z
Status : Analyzed
Published: 2025-06-16T21:15:24.010
Modified: 2025-07-16T14:32:59.367
Link: CVE-2025-47951
No data.