在 wger 2.5 之前的版本中,系统未能验证计划(routine)日期范围的最大持续时间,这使得经过身份验证的用户可以创建跨度任意长的训练计划。攻击者可以通过访问计划详情接口触发 的计算过程,迫使服务器在每次请求中执行数千次迭代,从而耗尽工作线程资源,导致无法为合法用户提供正常服务(即拒绝服务攻击,DoS)。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wger-project | wger | < 2.5 |
affected |
2.5 |
unaffected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wger-project | wger | 0 ~ 2.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86254 | 6.8 MEDIUM | wger Incomplete Authorization Fix Cross-Tenant Account Deletion |
| CVE-2026-86256 | 5.4 MEDIUM | wger before 2.6 Open Redirect via trainer-login next parameter |
| CVE-2026-86257 | 5.4 MEDIUM | wger before 2.6 CSV Formula Injection via member export |
No comments yet