Web Vulnerability in Weblate Affects User Privacy and API Security
CVE-2025-67715

4.3MEDIUM

Key Information:

Vendor

Weblateorg

Status
Vendor
CVE Published:
16 December 2025

What is CVE-2025-67715?

Weblate, a web-based localization tool, had a vulnerability that allowed unauthorized access to user notification settings and the capability to list all users via its API. This issue impacted versions prior to 5.15 and has since been resolved in the latest release. Users of earlier versions are strongly encouraged to update to mitigate risks associated with unauthorized access to sensitive user data.

Affected Version(s)

weblate < 5.15

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.