Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wger — Vulnerabilities & Security Advisories 13

All 13 CVE vulnerabilities found in wger, with AI-generated Chinese analysis, references, and POCs.

Vendor: wger-project

CVE ID Title CVSS Severity Published
CVE-2026-86257 wger before 2.6 CSV Formula Injection via member export CWE-1236 5.4 Medium 2026-09-06
CVE-2026-86256 wger before 2.6 Open Redirect via trainer-login next parameter CWE-601 5.4 Medium 2026-09-06
CVE-2026-86255 wger before 2.5 Uncontrolled Resource Consumption via date_sequence CWE-400 6.5 Medium 2026-09-06
CVE-2026-86254 wger Incomplete Authorization Fix Cross-Tenant Account Deletion CWE-862 6.8 Medium 2026-09-06
CVE-2026-82544 wger-project wger Password Reset gym.py reset_user_password cross-site request forgery CWE-352 4.3 Medium 2026-08-30
CVE-2026-43977 wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API CWE-639 7.5 High 2026-07-16
CVE-2026-43978 wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers CWE-269 8.1 High 2026-07-16
CVE-2026-43948 wger: cross-tenant password reset and plaintext disclosure via gym=None bypass CWE-863 9.9 Critical 2026-05-12
CVE-2026-40474 wger has Broken Access Control in the Global Gym Configuration Update Endpoint CWE-284 7.6 High 2026-04-17
CVE-2026-40353 wger: Stored XSS via Unescaped License Attribution Fields CWE-79 5.4AI Medium AI 2026-04-17
CVE-2026-27839 wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup CWE-639 4.3 Medium 2026-02-26
CVE-2026-27838 wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data CWE-639 3.1 Low 2026-02-26
CVE-2026-27835 wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data CWE-639 4.3 Medium 2026-02-26

All 13 known CVE vulnerabilities affecting wger with full Chinese analysis, references, and POCs where available.