VulnSea

wger has 8 CVEs on record. 1 was published in the last 90 days. The busiest recent month was February 2026 with 3. The median CVSS is 6.0 (medium). None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.0
Publish → KEV
Last 90 days
1 prev 4

Weakness classes

Products

  • wger 8
8
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

wger vulnerabilities

CVEs affecting wger, newest first. Open any entry for full detail, references, and exploit status.

8 CVEsRSS

CVE-2026-86255Medium· 6.5
2w ago

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endp…

Sunlitwger · wgerEPSS 0.25%via NVD
CVE-2026-43977High· 7.5
4mo ago

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

Twilightwger · wgerEPSS 0.39%via OSV
CVE-2026-43978High· 8.1
4mo ago

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

Twilightwger · wgerEPSS 0.37%via OSV
CVE-2026-40474High· 7.6
5mo ago

wger has Broken Access Control in Global Gym Configuration Update Endpoint

wger has Broken Access Control in Global Gym Configuration Update Endpoint

Twilightwger · wgerEPSS 0.33%via OSV
CVE-2026-40353Medium· 5.4
5mo ago

wger has Stored XSS via Unescaped License Attribution Fields

wger has Stored XSS via Unescaped License Attribution Fields

Sunlitwger · wgerEPSS 0.21%via OSV
CVE-2026-27835Medium· 4.3
6mo ago

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data

Sunlitwger · wgerEPSS 0.26%via OSV
CVE-2026-27839Medium· 4.3
6mo ago

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup

Sunlitwger · wgerEPSS 0.26%via OSV
CVE-2026-27838Low· 3.1
6mo ago

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data

Sunlitwger · wgerEPSS 0.24%via OSV
wger vulnerabilities (CVEs) · VulnSea