CVE-2025-47951
published 2025-06-16CVE-2025-47951: Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate…
PriorityP428medium4.9CVSS 3.1
AVNACHPRLUINSCCLILAN
EPSS
0.27%
18.7th percentile
Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| weblate | weblate | < 5.12 | 5.12 |
| weblate | weblate | >= 0 < 5.12 | 5.12 |
| weblateorg | weblate | < 5.12 | 5.12 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Weblate lacks rate limiting when verifying second factor
ghsa·2025-06-16
CVE-2025-47951 [MEDIUM] CWE-307 Weblate lacks rate limiting when verifying second factor
Weblate lacks rate limiting when verifying second factor
### Impact
The verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing.
### Patches
This issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918.
### References
Thanks to [obscuredeer](https://hackerone.com/obscuredeer) for reporting this [issue at HackerOne](https://hackerone.com/reports/3150564).
OSV
Weblate lacks rate limiting when verifying second factor
osv·2025-06-16
CVE-2025-47951 [MEDIUM] Weblate lacks rate limiting when verifying second factor
Weblate lacks rate limiting when verifying second factor
### Impact
The verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing.
### Patches
This issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918.
### References
Thanks to [obscuredeer](https://hackerone.com/obscuredeer) for reporting this [issue at HackerOne](https://hackerone.com/reports/3150564).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/WeblateOrg/weblate/commit/f806293451248c5d95e45b3b507e9d158bc4f384https://github.com/WeblateOrg/weblate/pull/14918https://github.com/WeblateOrg/weblate/releases/tag/weblate-5.12.1https://github.com/WeblateOrg/weblate/security/advisories/GHSA-57jg-m997-cx3qhttps://hackerone.com/reports/3150564
2025-06-16
Published