Components
Vulnerabilities
Pricing
MCP
Docs
Sign up
Login
Find vulnerabilities. Fix fast with AI.
Search components by package, version, or CVE to get started.
Ecosystem
Package
Version
Vulnerabilities
CVE-2025-60538
CVE-2025-60538
A lack of rate limiting in the login page of shiori v1.7.4 and below allows attackers to bypass authentication via a brute force attack.
Published Jan 14, 2026
https://github.com/advisories/GHSA-p52w-7rhw-9m67
CVSS Score
Medium
6.5
Components Impacted
Components Impacted
Security Details
Security Details
Sonatype Research
Sonatype Research
Ecosystem
Package
Version
Ecosystem
Package
Version
golang
github.com/go-shiori/shiori
v1.5.0
golang
github.com/go-shiori/shiori
v1.5.1
golang
github.com/go-shiori/shiori
v1.5.2
golang
github.com/go-shiori/shiori
v1.5.3
golang
github.com/go-shiori/shiori
v1.5.4
golang
github.com/go-shiori/shiori
v1.5.5-rc.1
golang
github.com/go-shiori/shiori
v1.5.5-rc.2
golang
github.com/go-shiori/shiori
v1.5.5
golang
github.com/go-shiori/shiori
v1.6.0-rc.1
golang
github.com/go-shiori/shiori
v1.6.0-rc.2
golang
github.com/go-shiori/shiori
v1.6.0-rc.3
golang
github.com/go-shiori/shiori
v1.6.0-rc.4
golang
github.com/go-shiori/shiori
v1.6.0-rc.5
golang
github.com/go-shiori/shiori
v1.6.0-rc.6
golang
github.com/go-shiori/shiori
v1.6.0-rc.7
golang
github.com/go-shiori/shiori
v1.6.0
golang
github.com/go-shiori/shiori
v1.6.1
golang
github.com/go-shiori/shiori
v1.6.2
golang
github.com/go-shiori/shiori
v1.6.3
golang
github.com/go-shiori/shiori
v1.7.0-rc.1
golang
github.com/go-shiori/shiori
v1.7.0-rc.2
golang
github.com/go-shiori/shiori
v1.7.0-rc.3
golang
github.com/go-shiori/shiori
v1.7.0
golang
github.com/go-shiori/shiori
v1.7.1
golang
github.com/go-shiori/shiori
v1.7.2-rc.1
golang
github.com/go-shiori/shiori
v1.7.2
golang
github.com/go-shiori/shiori
v1.7.3
golang
github.com/go-shiori/shiori
v1.7.4
1-28 of 28
CVE-2025-60538 | Components Impacted | Sonatype Guide | Sonatype Guide