Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2700▼ 69 respecto a la semana anterior
Críticas / altas1449▲ 307 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.28% | — | WgerAIMicrosoft ExcelAILibreoffice CalcAI | 6/9/2026 | 8/9/2026 | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code when admins open the exported file in Excel or LibreOffice Calc. | |
| Aplazada | Media (5.1) | 0.23% | — | WgerAI | 6/9/2026 | 9/9/2026 | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET parameter via HttpResponseRedirect() without validating it with… | |
| Aplazada | Media (6.1) | 0.37% | — | WgerAI | 6/9/2026 | 8/9/2026 | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff with gym=None to delete, deactivate, or activate any other user with gym=None.… | |
| Aplazada | Alta (7.1) | 0.44% | — | WgerAI | 6/9/2026 | 18/9/2026 | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcing the server to iterate thousands of times per request and exhaust… | |
| Aplazada | Media (5.3) | 0.24% | — | WgerAI | 30/8/2026 | 31/8/2026 | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called… | |
| Aplazada | Alta (8.1) | 0.37% | — | WgerAI | 16/7/2026 | 17/7/2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint. Once a trainer performs a legitimate switch into a low-privileged user, the… | |
| Aplazada | Alta (7.5) | 0.39% | — | WgerAI | 16/7/2026 | 17/7/2026 | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ actions on a routine they do not own. The vulnerability exists in RoutineViewSet… | |
| Aplazada | Crítica (9.9) | 0.44% | — | WgerAI | 12/5/2026 | 17/6/2026 | wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != None as False, silently bypassing the guard when both the attacker and victim… | |
| Analizada | Alta (7.6) | 0.40% | — | Wger | 17/4/2026 | 17/6/2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permission is never enforced at runtime. Since GymConfig is an ownerless singleton, any… | |
| Analizada | Media (5.1) | 0.25% | — | Wger | 17/4/2026 | 17/6/2026 | wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) without escaping, and templates render the result using Django's |safe filter. An… | |
| Analizada | Media (4.3) | 0.31% | — | Wger | 26/2/2026 | 17/6/2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call that bypasses the user-scoped queryset. Any authenticated user can read another user's private nutrition plan data,… | |
| Analizada | Baja (3.5) | 0.25% | — | Wger | 26/2/2026 | 17/6/2026 | wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` — no user ID is included. When a victim has previously accessed their routine via the API, an attacker… | |
| Analizada | Media (4.3) | 0.30% | — | Wger | 26/2/2026 | 17/6/2026 | wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data because their `get_queryset()` calls `.all()` instead of filtering by the authenticated user. Any registered user can… | |
| Modificada | Alta (8.8) | 0.40% | — | Wger Workout Manager | 8/8/2023 | 17/6/2026 | Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templates/user/overview.html, core/views/user.py, and… | |
| Modificada | Media (5.4) | 0.59% | — | Wger Workout Manager | 8/8/2023 | 17/6/2026 | Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient function in the templates/ingredients/view.html, models/ingredients.py, and views/ingredients.py components. | |
| Modificada | Crítica (9.8) | 0.71% | — | Wger | 24/11/2022 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2. |