Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-3pmh-24wp-xpf4 | Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 16 Dec 2025 00:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue. | |
| Title | Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR) | |
| Weaknesses | CWE-284 CWE-285 |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-12-16T00:07:42.829Z
Reserved: 2025-12-10T17:47:36.418Z
Link: CVE-2025-67715
No data.
Status : Received
Published: 2025-12-16T01:15:52.057
Modified: 2025-12-16T01:15:52.057
Link: CVE-2025-67715
No data.
OpenCVE Enrichment
No data.
Github GHSA