Back to search
CVE-2025-49134
Published: Jun 16, 2025
Modified: Jun 17, 2025
PUBLISHED
Description
Weblate is a web based localization tool. Prior to version 5.12, the audit log notifications included the full IP address of the acting user. This could be obtained by third-party servers such as SMTP relays, or spam filters. This issue has been patched in version 5.12.
| Vendor | Product | Versions |
|---|---|---|
WeblateOrg | weblate | affected < 5.12 |
Weaknesses (CWE)
References
https://github.com/WeblateOrg/weblate/pull/15102
x_refsource_MISC
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now