CVE-2022-2650 — Improper Restriction of Excessive Authentication Attempts in wger
In April 2022, I came across wger, a workout application that had a demo site and allowed for standalone installation. I found the application would not block brute-force attacks against the login page. Very simple, very straightforward. This led to my first CVE: <code class="language-plaintex...
Published on June 25, 2026 | 0 min read