VulnSea

wger vulnerabilities

CVEs whose affected-version data names the wger package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

11 CVEsRSS

CVE-2026-86257Medium· 5.4PoC⚖ disputed
2w ago

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or ex…

Twilightwger-project · wgerEPSS 0.17%via NVD
CVE-2026-86256Medium· 5.4PoC
2w ago

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET param…

Twilightwger-project · wgerEPSS 0.18%via NVD
CVE-2026-86255Medium· 6.5
2w ago

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endp…

Sunlitwger · wgerEPSS 0.25%via NVD
CVE-2026-86254Medium· 6.8PoC
2w ago

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff…

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff…

Twilightwger-project · wgerEPSS 0.22%via NVD
CVE-2026-43977High· 7.5
4mo ago

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

Twilightwger · wgerEPSS 0.39%via OSV
CVE-2026-43978High· 8.1
4mo ago

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

Twilightwger · wgerEPSS 0.37%via OSV
CVE-2026-40474High· 7.6
5mo ago

wger has Broken Access Control in Global Gym Configuration Update Endpoint

wger has Broken Access Control in Global Gym Configuration Update Endpoint

Twilightwger · wgerEPSS 0.33%via OSV
CVE-2026-40353Medium· 5.4
5mo ago

wger has Stored XSS via Unescaped License Attribution Fields

wger has Stored XSS via Unescaped License Attribution Fields

Sunlitwger · wgerEPSS 0.21%via OSV
CVE-2026-27835Medium· 4.3
6mo ago

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

Sunlitwger · wgerEPSS 0.26%via OSV
CVE-2026-27839Medium· 4.3
6mo ago

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

Sunlitwger · wgerEPSS 0.26%via OSV
CVE-2026-27838Low· 3.1
6mo ago

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

Sunlitwger · wgerEPSS 0.24%via OSV
wger vulnerabilities (CVEs) · VulnSea