Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.
References
Configurations
History
No history.
Information
Published : 2025-12-15 21:15
Updated : 2025-12-18 21:25
NVD link : CVE-2025-64725
Mitre link : CVE-2025-64725
CVE.ORG link : CVE-2025-64725
JSON object : View
Products Affected
weblate
- weblate
CWE
CWE-286
Incorrect User Management
