Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-18400 | Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12. |
Github GHSA |
GHSA-57jg-m997-cx3q | Weblate lacks rate limiting when verifying second factor |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 16 Jul 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Weblate
Weblate weblate |
|
| CPEs | cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Weblate
Weblate weblate |
Tue, 17 Jun 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 16 Jun 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. Prior to version 5.12, the verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing. This issue has been patched in version 5.12. | |
| Title | Weblate lacks rate limiting when verifying second factor | |
| Weaknesses | CWE-307 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-06-17T18:52:13.582Z
Reserved: 2025-05-14T10:32:43.531Z
Link: CVE-2025-47951
Updated: 2025-06-17T18:52:08.109Z
Status : Analyzed
Published: 2025-06-16T21:15:24.010
Modified: 2025-07-16T14:32:59.367
Link: CVE-2025-47951
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA