İçeriğe atla
Noroxi

wger kayıtları

wger üreticisine ait 8 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
0 · %0
Pre-auth RCE
0
Düzeltme kaydı olan
%37,5
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

8 kayıt
  • CVE-2022-2650
    39İzleyin

    Improper Restriction of Excessive Authentication Attempts in wger-project/wger

    KritikCVSS 9,8İstismar yokEPSS %1

    wger · wger24 Kas 2022

  • CVE-2023-38759
    35İzleyin

    Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via

    YüksekCVSS 8,8İstismar yokEPSS %0

    wger · workout manager8 Ağu 2023

  • CVE-2026-40474
    30İzleyin

    wger has Broken Access Control in the Global Gym Configuration Update Endpoint

    YüksekCVSS 7,6İstismar yokEPSS %0

    wger · wger17 Nis 2026

  • CVE-2023-38758
    21İzleyin

    Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the licens

    OrtaCVSS 5,4İstismar yokEPSS %1

    wger · workout manager8 Ağu 2023

  • CVE-2026-40353
    20İzleyin

    wger: Stored XSS via Unescaped License Attribution Fields

    OrtaCVSS 5,1İstismar yokEPSS %0

    wger · wger17 Nis 2026

  • CVE-2026-27839
    17İzleyin

    wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

    OrtaCVSS 4,3İstismar yokEPSS %0

    wger · wger26 Şub 2026

  • CVE-2026-27835
    17İzleyin

    wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

    OrtaCVSS 4,3İstismar yokEPSS %0

    wger · wger26 Şub 2026

  • CVE-2026-27838
    14İzleyin

    wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

    DüşükCVSS 3,5İstismar yokEPSS %0

    wger · wger26 Şub 2026