Roland Geider
4 exploits
Active since Feb 2026
wger has Broken Access Control in the Global Gym Configuration Update Endpoint
CVSS 7.6
wger < 2.4 - Authorization Bypass via Routine Detail Cache Key
CVSS 3.1
wger <= 2.4 - Authenticated Authorization Bypass via Nutritional Values Endpoint
CVSS 4.3
wger <= 2.4 - Unauthorized Data Access via RepetitionsConfigViewSet and MaxRepetitionsConfigViewSet
CVSS 4.3