CVE-2025-67715

Severity CVSS v4.0:
Pending analysis
Type:
CWE-284 Improper Access Control
Publication date:
16/12/2025
Last modified:
17/12/2025

Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:weblate:weblate:*:*:*:*:*:*:*:* 5.15 (excluding)