CVE-2025-67715Improper Access Control in Weblate

Severity
4.3MEDIUMNVD
EPSS
0.0%
top 97.66%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
Latest updateDec 15
PublishedDec 16

Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages3 packages

NVDweblate/weblate< 5.15
PyPIweblate/weblate< 5.15
CVEListV5weblateorg/weblate< 5.15

Patches

🔴Vulnerability Details

2
OSV
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)2025-12-15
GHSA
Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)2025-12-15

🕵️Threat Intelligence

1
Wiz
CVE-2025-67715 Impact, Exploitability, and Mitigation Steps | Wiz