CVE-2025-64725: Weblate

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Weblate is a web based localization tool. In versions prior to 5.15, it was possible to accept an invitation opened by a different user. Version 5.15. contains a patch. As a workaround, avoid leaving one's Weblate sessions with an invitation opened unattended.

Affected products

  • Weblate Weblate: before 5.15 (fixed in 5.15)

Published 2025-12-15. Last modified 2026-10-07.