CVE-2025-64116: Leepeuker Movary

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers to redirect authenticated users to arbitrary external sites. This vulnerability is fixed in 0.69.0.

Affected products

  • Leepeuker Movary: before 0.69.0 (fixed in 0.69.0)

Published 2025-10-30. Last modified 2026-10-07.