Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
Metrics
Affected Vendors & Products
References
History
Wed, 16 Jul 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Weblate
Weblate weblate |
|
CPEs | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | |
Vendors & Products |
Weblate
Weblate weblate |
Tue, 17 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 16 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12. | |
Title | Weblate lacks rate limiting when verifying second factor | |
Weaknesses | CWE-307 | |
References |
|
|
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-06-16T20:57:52.509Z
Updated: 2025-06-17T18:52:13.582Z
Reserved: 2025-05-14T10:32:43.531Z
Link: CVE-2025-47951

Updated: 2025-06-17T18:52:08.109Z

Status : Analyzed
Published: 2025-06-16T21:15:24.010
Modified: 2025-07-16T14:32:59.367
Link: CVE-2025-47951

No data.