CVE-2026-46437

CVE-2026-46437 published: wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their passwo...

View full NVD advisory → ← Back to CVE watch