CVE-2025-47951Medium· 4.9▾ SunlitWeblate lacks rate limiting when verifying second factor
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.2%
Last analysed / modified upstream
0.2% → 0.3%
The verification of the second factor was not subject to rate limiting. The absence of rate limiting on the second factor endpoint allows an attacker with valid credentials to automate OTP guessing.
This issue has been addressed in Weblate 5.12 via https://github.com/WeblateOrg/weblate/pull/14918.
Thanks to obscuredeer for reporting this issue at HackerOne.
weblate < 5.12Upgrade to a patched release:
weblate 5.12Connected by shared product, vendor, weakness, or advisory.
CVE-2025-49134Medium· 5.3Weblate exposes personal IP address via e-mail
CVE-2026-55227Medium· 4.3Private Weblate projects vulnerable to observable object existence disclosure via globally scoped object lookups
CVE-2026-55228High· 8.1Weblate has IDOR in GroupViewSet that allows authenticated project manager to gain unauthorized read access to any private project
CVE-2026-34244Medium· 5.0Weblate: SSRF via Project-Level Machinery Configuration
CVE-2026-27457Medium· 4.3Weblate: Missing access control for the AddonViewSet API exposes all addon configurations
CVE-2026-33212Low· 3.1Weblate: Improper access control for pending tasks in API