Skip to content
Noroxi

wger records

8 published records for vendor wger.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
37.5%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2022-2650
    39Monitor

    Improper Restriction of Excessive Authentication Attempts in wger-project/wger

    CriticalCVSS 9.8No exploitEPSS 1%

    wger · wgerNov 24, 2022

  • Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via

    HighCVSS 8.8No exploitEPSS 0%

    wger · workout managerAug 8, 2023

  • wger has Broken Access Control in the Global Gym Configuration Update Endpoint

    HighCVSS 7.6No exploitEPSS 0%

    wger · wgerApr 17, 2026

  • Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the licens

    MediumCVSS 5.4No exploitEPSS 1%

    wger · workout managerAug 8, 2023

  • wger: Stored XSS via Unescaped License Attribution Fields

    MediumCVSS 5.1No exploitEPSS 0%

    wger · wgerApr 17, 2026

  • wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

    MediumCVSS 4.3No exploitEPSS 0%

    wger · wgerFeb 26, 2026

  • wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

    MediumCVSS 4.3No exploitEPSS 0%

    wger · wgerFeb 26, 2026

  • wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

    LowCVSS 3.5No exploitEPSS 0%

    wger · wgerFeb 26, 2026