CVE-2025-64116: Leepeuker Movary
Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.
Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers to redirect authenticated users to arbitrary external sites. This vulnerability is fixed in 0.69.0.
Affected products
- Leepeuker Movary: before 0.69.0 (fixed in 0.69.0)
Published 2025-10-30. Last modified 2026-10-07.