Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

wger-project — Vulnerabilities & Security Advisories 14

Browse all 14 CVE security advisories affecting wger-project. AI-powered Chinese analysis, POCs, and references for each vulnerability.

The wger-project is a fitness management platform enabling users to track workouts, nutrition, and weight progress. Historically, it has been susceptible to multiple vulnerability classes including cross-site scripting (XSS), remote code execution (RCE), and privilege escalation, with six CVEs documented. These vulnerabilities often stem from insufficient input validation and improper access controls in its web interface. The project maintains an open-source nature with regular security updates, though its widespread deployment in fitness environments necessitates ongoing vigilance against exploitation. No major security incidents have been widely reported, but the presence of multiple CVEs indicates consistent security challenges requiring proactive mitigation by implementers.

Top products by wger-project: wger wger-project/wger
CVE ID Title CVSS Severity Published
CVE-2026-86257 wger before 2.6 CSV Formula Injection via member export — wger CWE-1236 5.4 Medium 2026-09-06
CVE-2026-86256 wger before 2.6 Open Redirect via trainer-login next parameter — wger CWE-601 5.4 Medium 2026-09-06
CVE-2026-86255 wger before 2.5 Uncontrolled Resource Consumption via date_sequence — wger CWE-400 6.5 Medium 2026-09-06
CVE-2026-86254 wger Incomplete Authorization Fix Cross-Tenant Account Deletion — wger CWE-862 6.8 Medium 2026-09-06
CVE-2026-82544 wger-project wger Password Reset gym.py reset_user_password cross-site request forgery — wger CWE-352 4.3 Medium 2026-08-30
CVE-2026-43977 wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API — wger CWE-639 7.5 High 2026-07-16
CVE-2026-43978 wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers — wger CWE-269 8.1 High 2026-07-16
CVE-2026-43948 wger: cross-tenant password reset and plaintext disclosure via gym=None bypass — wger CWE-863 9.9 Critical 2026-05-12
CVE-2026-40474 wger has Broken Access Control in the Global Gym Configuration Update Endpoint — wger CWE-284 7.6 High 2026-04-17
CVE-2026-40353 wger: Stored XSS via Unescaped License Attribution Fields — wger CWE-79 5.4AI Medium AI 2026-04-17
CVE-2026-27839 wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup — wger CWE-639 4.3 Medium 2026-02-26
CVE-2026-27838 wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data — wger CWE-639 3.1 Low 2026-02-26
CVE-2026-27835 wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data — wger CWE-639 4.3 Medium 2026-02-26
CVE-2022-2650 Improper Restriction of Excessive Authentication Attempts in wger-project/wger — wger-project/wger CWE-307 9.8 - 2022-11-24

This page lists every published CVE security advisory associated with wger-project. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.