wger
PyPI14 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting wgerpage 1 of 1
- CVE-2022-2650CRITICALCVSS 9.8EG 9.8✓ Fixed in 2.22022-11-24
vulnerable: 1.1 ... 2.1 (14 versions)
Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2.
- CVE-2023-38758MEDIUMCVSS 5.4EG 5.42023-08-08
vulnerable: 1.1 ... 2.1 (14 versions)
Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient function in the templates/ingredients/view.html, models/ingred…
- CVE-2023-38759HIGHCVSS 8.8EG 8.82023-08-08
vulnerable: 1.1 ... 2.1 (14 versions)
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/views/gym.py, templates/gym/reset_user_password.html, templ…
- CVE-2026-27835MEDIUMCVSS 4.3EG 4.32026-02-26
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetition config data because their `get_queryset()` calls `.all(…
- CVE-2026-27838LOWCVSS 3.5EG 3.52026-02-26
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, ache keys are scoped only by `pk` — no user ID is includ…
- CVE-2026-27839MEDIUMCVSS 4.3EG 4.32026-02-26
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk)` — a raw ORM call that bypasses the user-scoped queryse…
- CVE-2026-40353MEDIUMCVSS 5.4EG 5.42026-04-17
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating user-controlled license fields (such as license_author) wit…
- CVE-2026-40474HIGHCVSS 7.6EG 7.62026-04-17
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits WgerFormMixin instead of WgerPermissionMixin, so the permissi…
- CVE-2026-43948CRITICALCVSS 9.9EG 9.9✓ Fixed in 2.62026-05-12
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. Prior to 2.6, the reset_user_password and gym_permissions_user_edit views in wger perform a gym-scope authorization check using Python object comparison (!=) that evaluates None != N…
- CVE-2026-43977HIGHCVSS 7.5EG 7.52026-07-16
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, any authenticated user can read another user's private workout session notes, exercise history, and training statistics by calling the /logs/ and /stats/ ac…
- CVE-2026-43978HIGHCVSS 8.1EG 8.12026-07-16
vulnerable: 1.1 ... 2.1 (14 versions)
wger is a free, open-source workout and fitness manager. In versions prior to 2.6, a gym trainer can escalate their session to any higher-privileged account (gym manager, general manager) by chaining two calls to the trainer-login endpoint…
- CVE-2026-86255MEDIUMCVSS 6.5EG 6.52026-09-06
vulnerable: 1.1 ... 2.1 (14 versions)
wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoi…
- CVE-2026-86256MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.62026-09-06
vulnerable: 1.1 ... 2.1 (14 versions)
wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET paramet…
- CVE-2026-86257MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.62026-09-06
vulnerable: 1.1 ... 2.1 (14 versions)
wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or exec…
Check whether wger is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for wger CVEs against the assets you own.
Start Free Scan →