Authorization Bypass in Ribblr - Crochet & Knitting iOS Application
CVE-2025-15626

5.3MEDIUM

Key Information:

Vendor

Ribblr

Vendor
CVE Published:
27 April 2026

What is CVE-2025-15626?

An authenticated user of the Ribblr Crochet & Knitting iOS application may exploit a vulnerability that allows unauthorized access to restricted areas of the app. This issue poses significant risks to user data and security protocols, as it enables breaches that should be restricted based on user permissions.

Affected Version(s)

Crotchet and Knitting iOS 2.5

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aino Kivilahti
.