Known Vulnerabilities for Wger by Wger-project
Listed below are 7 of the newest known vulnerabilities associated with "Wger" by "Wger-project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86257 json | wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym mem... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-86256 json | wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/vie... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-86255 json | wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routine... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-86254 json | wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain t... | Not Provided | 2026-09-06 | 2026-09-06 |
| CVE-2026-82544 json | A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the fil... | Not Provided | 2026-08-30 | 2026-08-31 |
| CVE-2026-43978 json | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session t... | Not Provided | 2026-07-16 | 2026-07-17 |
| CVE-2026-43977 json | wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another us... | Not Provided | 2026-07-16 | 2026-07-17 |