CVE-2025-60538: Medium severity shiori vulnerability
Published Jan 9, 2026
·Updated
A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.
Affected Software
3 affected components
shiori<=1.7.4
go/github.com/go-shiori/shiori<=1.7.4
Go-shiori Shiori Go<=1.7.4
Event History
Jan 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:16 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
Affected Software
Advisory Published
via GitHub·09:31 PM
Data Sourced
via GitHub·09:31 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-60538?
CVE-2025-60538 is considered a high severity vulnerability due to its potential for exploitation through brute force attacks.
2
How do I fix CVE-2025-60538?
To fix CVE-2025-60538, implement rate limiting on the login page of shiori to mitigate brute force attack risks.
3
What versions of shiori are affected by CVE-2025-60538?
CVE-2025-60538 affects shiori versions 1.7.4 and below.
4
Can CVE-2025-60538 lead to unauthorized access?
Yes, CVE-2025-60538 allows attackers to bypass authentication, potentially leading to unauthorized access.
5
Is there a patch available for CVE-2025-60538?
As of now, ensure you check the official shiori repository for updates or patches addressing CVE-2025-60538.