Wger
Wger: vulnerabilities and CVEs
Wger has 14 published vulnerabilities, 13 of them in the last 12 months. 2 are rated critical and 0 are listed by CISA as actively exploited.
CVEs14
Last 12 months13
Critical2
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86257 | Medium (4.8) | 0.28% | — | Sep 6, 2026 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to… |
| CVE-2026-86256 | Medium (5.1) | 0.23% | — | Sep 6, 2026 | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the… |
| CVE-2026-86254 | Medium (6.1) | 0.37% | — | Sep 6, 2026 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper,… |
| CVE-2026-86255 | High (7.1) | 0.44% | — | Sep 6, 2026 | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via… |
| CVE-2026-82544 | Medium (5.3) | 0.24% | — | Aug 30, 2026 | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to… |
| CVE-2026-43978 | High (8.1) | 0.37% | — | Jul 16, 2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the… |
| CVE-2026-43977 | High (7.5) | 0.39% | — | Jul 16, 2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the… |
| CVE-2026-43948 | Critical (9.9) | 0.44% | — | May 12, 2026 | wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that… |
| CVE-2026-40474 | High (7.6) | 0.40% | — | Apr 17, 2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of… |
| CVE-2026-40353 | Medium (5.1) | 0.25% | — | Apr 17, 2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as… |
| CVE-2026-27839 | Medium (4.3) | 0.31% | — | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call that bypasses the… |
| CVE-2026-27838 | Low (3.5) | 0.25% | — | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` — no… |
| CVE-2026-27835 | Medium (4.3) | 0.30% | — | Feb 26, 2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data because their… |
| CVE-2022-2650 | Critical (9.8) | 0.71% | — | Nov 24, 2022 | Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.