A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.
Metrics
Affected Vendors & Products
References
History
Fri, 09 Jan 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-290 | |
| Metrics |
cvssV3_1
|
Fri, 09 Jan 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-01-09T21:21:49.698Z
Reserved: 2025-09-26T00:00:00.000Z
Link: CVE-2025-60538
Updated: 2026-01-09T21:21:44.156Z
Status : Received
Published: 2026-01-09T21:16:13.340
Modified: 2026-01-09T22:16:00.110
Link: CVE-2025-60538
No data.
OpenCVE Enrichment
No data.