Weblate Web-Based Localization Tool Session Vulnerability
CVE-2025-64725
1LOW
What is CVE-2025-64725?
Weblate, a web-based localization tool, has a vulnerability in its session management system. Versions prior to 5.15 allow users to accept invitations that were opened by different users, potentially compromising user sessions. As a security measure, users are advised to avoid leaving sessions open with invitations unattended. The issue has been addressed in version 5.15, which contains a patch to mitigate the risks associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
weblate < 5.15
References
CVSS V4
Score:
1
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
