VDB
CVE-2025-64326
CVE-2025-64326
PUBLISHED
CVSS 2.5999999046325684 LOW
Weblate leaks the IP of project member inviting user to be reviewer in Audit log
EPSS 0.19% · 8.3th percentile
Risk Scores
CVSS 3.1
2.5999999046325684
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:N/A:N
EPSS Score
0.19%
8.3th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | weblate | 0 |
| weblate | weblate | 0 |
| WeblateOrg | weblate | * |
Timeline
- Nov 5, 2025 CVE Published
- Nov 7, 2025 EPSS Score
- Nov 12, 2025 EPSS Score
- Nov 18, 2025 EPSS Score
- Nov 23, 2025 EPSS Score
- Nov 29, 2025 EPSS Score
- Dec 4, 2025 EPSS Score
- Dec 9, 2025 EPSS Score
- Dec 15, 2025 EPSS Score
- Dec 20, 2025 EPSS Score
- Dec 25, 2025 EPSS Score
- Dec 31, 2025 EPSS Score
References
- https://github.com/WeblateOrg/weblate/security/advisories/GHSA-gr35-vpx2-qxhc url
- https://github.com/WeblateOrg/weblate/pull/16781 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-64326 advisory
- https://github.com/WeblateOrg/weblate/commit/b847e9756a0a6f7659ef20fa9f34846ca862c574 url
- https://github.com/WeblateOrg/weblate package