CVE-2025-67715: Weblate has Systematic User and Project Enumeration via Broken Authorization in REST API (IDOR)
Impact
It was possible to retrieve user notification settings or list all users via API.
Patches
https://github.com/WeblateOrg/weblate/pull/17256
References
Thanks to Hector Ruiz Ruiz & NaxusAI for responsibly disclosing this vulnerability to Weblate.
Other sources
Weblate is a web based localization tool. In versions prior to 5.15, it was possible to retrieve user notification settings or list all users via API. Version 5.15 fixes the issue.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2025-67715?
CVE-2025-67715 has a high severity due to the potential unauthorized access to user notification settings and the ability to list all users via API.
How do I fix CVE-2025-67715?
To fix CVE-2025-67715, upgrade Weblate to version 5.15 or later as recommended in the patch.
What type of information can be exposed due to CVE-2025-67715?
CVE-2025-67715 can expose user notification settings and allow listing of all users through insecure API endpoints.
Who discovered the vulnerability CVE-2025-67715?
CVE-2025-67715 was responsibly disclosed by Hector Ruiz Ruiz and NaxusAI.
What is the affected software version for CVE-2025-67715?
CVE-2025-67715 affects Weblate versions up to but not including 5.15.