Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
CVE-2026-86257
  • github.com/wger-project/wger
wger before 2.6 CSV Formula Injection via member export 06 Sep
  • Fix available
  • Severity - 4.8 (Medium)
CVE-2026-86256
  • github.com/wger-project/wger
wger before 2.6 Open Redirect via trainer-login next parameter 06 Sep
  • Fix available
  • Severity - 5.1 (Medium)
CVE-2026-86255
  • github.com/wger-project/wger
wger before 2.5 Uncontrolled Resource Consumption via date_sequence 06 Sep
  • Fix available
  • Severity - 7.1 (High)
CVE-2026-82544
  • github.com/wger-project/wger
wger-project wger Password Reset gym.py reset_user_password cross-site request forgery 30 Aug
  • Fix available
  • Severity - 5.3 (Medium)
CVE-2026-43977
  • github.com/wger-project/wger
wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API 16 Jul
  • Fix available
  • Severity - 7.5 (High)
CVE-2026-43978
  • github.com/wger-project/wger
wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers 16 Jul
  • Fix available
  • Severity - 8.1 (High)
PYSEC-2026-3420
  • PyPI/wger
wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager 13 Jul
  • No fix available
  • Severity - 8.1 (High)
PYSEC-2026-3421
  • PyPI/wger
wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API 13 Jul
  • No fix available
  • Severity - 7.5 (High)
PYSEC-2026-3419
  • PyPI/wger
wger has Stored XSS via Unescaped License Attribution Fields 13 Jul
  • No fix available
  • Severity - 5.1 (Medium)
PYSEC-2026-3424
  • PyPI/wger
wger has Broken Access Control in Global Gym Configuration Update Endpoint 13 Jul
  • No fix available
  • Severity - 7.6 (High)
PYSEC-2026-3422
  • PyPI/wger
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup 13 Jul
  • No fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-3418
  • PyPI/wger
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data 13 Jul
  • No fix available
  • Severity - 3.1 (Low)
PYSEC-2026-3423
  • PyPI/wger
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data 13 Jul
  • No fix available
  • Severity - 4.3 (Medium)
PYSEC-2026-574
  • PyPI/wger
wger: cross-tenant password reset and plaintext disclosure via gym=None bypass 29 Jun
  • Fix available
  • Severity - 9.9 (Critical)
PYSEC-2026-573
  • PyPI/wger
wger vulnerable to brute force attempts 29 Jun
  • Fix available
  • Severity - 9.8 (Critical)
GHSA-mw8f-w6p8-xrf4
  • PyPI/wger
wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None 20 May
  • No fix available
  • Severity - 8.5 (High)