Wger-project

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 9
    Known Exploited: 0
    1
    Critical Level Threats
    3
    High Level Threats
    4
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-82544

    wger-project wger Password Reset gym.py reset_user_password cross-site request forgery

    Last Modified: Aug 31, 2026
    Published: Aug 30, 2026

    CVE-2026-43977

    wger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine API

    Last Modified: Jul 17, 2026
    Published: Jul 16, 2026

    CVE-2026-43978

    wger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managers

    Last Modified: Jul 17, 2026
    Published: Jul 16, 2026

    CVE-2026-43948

    wger: cross-tenant password reset and plaintext disclosure via gym=None bypass

    Last Modified: May 13, 2026
    Published: May 12, 2026

    CVE-2026-40474

    wger has Broken Access Control in the Global Gym Configuration Update Endpoint

    Last Modified: Apr 24, 2026
    Published: Apr 17, 2026
    Items Per Page
    Wger-Project Vulnerabilities & Security CVEs | CVE-DB