CVE-2025-67715

MEDIUM

Weblate < 5.15 - Unauthenticated User Information Disclosure via API

Title source: llm
STIX 2.1

Description

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.

References (2)

Core 2
Core References
Issue Tracking, Patch x_refsource_misc
https://github.com/WeblateOrg/weblate/pull/17256

Scores

CVSS v3 4.3
EPSS 0.0024
EPSS Percentile 14.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-284 CWE-285
Status published
Products (2)
pypi/Weblate 0 - 5.15PyPI
weblate/weblate < 5.15
Published Dec 16, 2025
Tracked Since Feb 18, 2026