« Back to list

Wger

Wger: vulnerabilities and CVEs

Wger has 14 published vulnerabilities, 13 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.

CVEs14
Last 12 months13
Critical2
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-86257Medium (4.8)0.28%—Sep 6, 2026
wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to…
CVE-2026-86256Medium (5.1)0.23%—Sep 6, 2026
wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the…
CVE-2026-86254Medium (6.1)0.37%—Sep 6, 2026
wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper,…
CVE-2026-86255High (7.1)0.44%—Sep 6, 2026
wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via…
CVE-2026-82544Medium (5.3)0.24%—Aug 30, 2026
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to…
CVE-2026-43978High (8.1)0.37%—Jul 16, 2026
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the…
CVE-2026-43977High (7.5)0.39%—Jul 16, 2026
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the…
CVE-2026-43948Critical (9.9)0.44%—May 12, 2026
wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that…
CVE-2026-40474High (7.6)0.40%—Apr 17, 2026
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of…
CVE-2026-40353Medium (5.1)0.25%—Apr 17, 2026
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as…
CVE-2026-27839Medium (4.3)0.31%—Feb 26, 2026
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call that bypasses the…
CVE-2026-27838Low (3.5)0.25%—Feb 26, 2026
wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` — no…
CVE-2026-27835Medium (4.3)0.30%—Feb 26, 2026
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data because their…
CVE-2022-2650Critical (9.8)0.71%—Nov 24, 2022
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services4
  2. T1078 Valid Accounts2
  3. T1005 Data from Local System1
  4. T1068 Exploitation for Privilege Escalation1
  5. T1190 Exploit Public-Facing Application1
  6. T1499.004 Application or System Exploitation1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Wger