wger-project wger
5 known vulnerabilities in wger-project wger, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-86257 CVSS 4.8 medium wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject…
- CVE-2026-86256 CVSS 5.1 medium wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py)…
- CVE-2026-86255 CVSS 7.1 high wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning…
- CVE-2026-86254 CVSS 6.1 medium wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original…
- CVE-2026-82544 CVSS 5.3 medium A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file…