Vulnerability Database
Blog
FAQ
Docs
arrow_forward
search
light_mode
dark_mode
Vulnerabilities
search
All ecosystems
2241261
AlmaLinux
5967
Alpaquita
16156
Alpine
4655
Android
3677
Azure Linux
17971
BellSoft Hardened Containers
770
Bitnami
9476
Chainguard
1048510
CleanStart
5235
CRAN
14
crates.io
2763
Debian
68939
Echo
7862
GHC
3
GIT
109017
GitHub Actions
55
Go
9328
Hackage
33
Hex
364
Julia
1713
Linux
29975
Mageia
6237
Maven
7050
MinimOS
148373
npm
229102
NuGet
1869
opam
29
openEuler
8900
openSUSE
14573
OSS-Fuzz
4018
Packagist
7101
Pub
11
PyPI
25463
Red Hat
23527
Rocky Linux
4342
Root
19624
RubyGems
5327
SUSE
23442
SwiftURL
60
TuxCare
9919
Ubuntu
65983
VSCode
21
Wolfi
293807
ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-86257
github.com/wger-project/wger
wger before 2.6 CSV Formula Injection via member export
06 Sep
Fix available
Severity - 4.8 (Medium)
CVE-2026-86256
github.com/wger-project/wger
wger before 2.6 Open Redirect via trainer-login next parameter
06 Sep
Fix available
Severity - 5.1 (Medium)
CVE-2026-86255
github.com/wger-project/wger
wger before 2.5 Uncontrolled Resource Consumption via date_sequence
06 Sep
Fix available
Severity - 7.1 (High)
CVE-2026-82544
github.com/wger-project/wger
wger-project wger Password Reset gym.py reset_user_password cross-site request forgery
30 Aug
Fix available
Severity - 5.3 (Medium)
CVE-2026-43977
github.com/wger-project/wger
wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API
16 Jul
Fix available
Severity - 7.5 (High)
CVE-2026-43978
github.com/wger-project/wger
wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers
16 Jul
Fix available
Severity - 8.1 (High)
PYSEC-2026-3420
PyPI/wger
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager
13 Jul
No fix available
Severity - 8.1 (High)
PYSEC-2026-3421
PyPI/wger
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API
13 Jul
No fix available
Severity - 7.5 (High)
PYSEC-2026-3419
PyPI/wger
wger has Stored XSS via Unescaped License Attribution Fields
13 Jul
No fix available
Severity - 5.1 (Medium)
PYSEC-2026-3424
PyPI/wger
wger has Broken Access Control in Global Gym Configuration Update Endpoint
13 Jul
No fix available
Severity - 7.6 (High)
PYSEC-2026-3422
PyPI/wger
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
13 Jul
No fix available
Severity - 4.3 (Medium)
PYSEC-2026-3418
PyPI/wger
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
13 Jul
No fix available
Severity - 3.1 (Low)
PYSEC-2026-3423
PyPI/wger
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
13 Jul
No fix available
Severity - 4.3 (Medium)
PYSEC-2026-574
PyPI/wger
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass
29 Jun
Fix available
Severity - 9.9 (Critical)
PYSEC-2026-573
PyPI/wger
wger vulnerable to brute force attempts
29 Jun
Fix available
Severity - 9.8 (Critical)
GHSA-mw8f-w6p8-xrf4
PyPI/wger
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None
20 May
No fix available
Severity - 8.5 (High)
Load more...
Vulnerability Database - OSV