CVE-2022-2650 — Improper Restriction of Excessive Authentication Attempts in wger

In April 2022, I came across wger, a workout application that had a demo site and allowed for standalone installation. I found the application would not block brute-force attacks against the login page. Very simple, very straightforward. This led to my first CVE: <code class="language-plaintex...
Published on June 25, 2026 | 0 min read

CVE-2026-39338: Blind XSS to Full Admin Takeover in ChurchCRM

SummaryWhile doing independent research on ChurchCRM (April 2026), an open-source church management platform, I found a Blind Cross-Site Scripting (XSS) vulnerability in the dashboard’s global search feature. On its own, that would have been a moderate finding. What mad...
Published on June 22, 2026 | 2 min read