wger has 8 CVEs on record. 1 was published in the last 90 days. The busiest recent month was February 2026 with 3. The median CVSS is 6.0 (medium). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.0
- Publish → KEV
- —
- Last 90 days
- 1 prev 4
Weakness classes
Products
- wger 8
Worst active — by depth score
CVE-2026-43978High· 8.1wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager45CVE-2026-40474High· 7.6wger has Broken Access Control in Global Gym Configuration Update Endpoint42CVE-2026-43977High· 7.5wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API41CVE-2026-86255Medium· 6.5wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods36CVE-2026-40353Medium· 5.4wger has Stored XSS via Unescaped License Attribution Fields30
wger vulnerabilities
CVEs affecting wger, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-86255Medium· 6.5wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods
wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endp…
CVE-2026-43977High· 7.5wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
CVE-2026-43978High· 8.1wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
CVE-2026-40474High· 7.6wger has Broken Access Control in Global Gym Configuration Update Endpoint
wger has Broken Access Control in Global Gym Configuration Update Endpoint
CVE-2026-40353Medium· 5.4wger has Stored XSS via Unescaped License Attribution Fields
wger has Stored XSS via Unescaped License Attribution Fields
CVE-2026-27835Medium· 4.3wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
CVE-2026-27839Medium· 4.3wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
CVE-2026-27838Low· 3.1wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data