Wger

Wger

19 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 07.10.2026 14:00:10
  • Zuletzt bearbeitet 07.10.2026 19:17:37

wger is a free, open-source workout and fitness manager. Prior to version 2.6, an authenticated attacker can inject arbitrary workout log entries into any other user's `SlotEntry` by supplying the victim's `slot_entry` ID in a `POST /api/v2/workoutlo...

  • EPSS -
  • Veröffentlicht 07.10.2026 13:58:34
  • Zuletzt bearbeitet 07.10.2026 14:46:03

wger is a free, open-source workout and fitness manager. Versions prior to 2.6 have a vulnerability in the authentication/session lifecycle of `wger` where bearer-style API credentials remain valid after a user logs out and after a user changes their...

  • EPSS -
  • Veröffentlicht 07.10.2026 13:55:19
  • Zuletzt bearbeitet 07.10.2026 15:17:20

wger is a free, open-source workout and fitness manager. Prior to version 2.6, a user with only the `gym_trainer` permission can deactivate any account in the same gym, including `gym_manager` and `general_gym_manager` accounts. The `UserDeactivateVi...

  • EPSS -
  • Veröffentlicht 07.10.2026 13:35:53
  • Zuletzt bearbeitet 07.10.2026 17:16:55

wger is a free, open-source workout and fitness manager. Prior to version 2.6, the `trainer_login` view in wger accepts GET requests and executes `django_login()` without any CSRF protection, because Django's `CsrfViewMiddleware` only enforces tokens...

  • EPSS -
  • Veröffentlicht 07.10.2026 13:33:11
  • Zuletzt bearbeitet 07.10.2026 18:17:20

wger is a free, open-source workout and fitness manager. Prior to version 2.6, five gym management views in wger apply a flawed gym-scope guard (`gym_a != gym_b`) that silently passes when both operands are `None`. A trainer with `gym.gym_trainer` an...

  • EPSS 0.17%
  • Veröffentlicht 06.09.2026 12:17:16
  • Zuletzt bearbeitet 08.09.2026 19:59:42

wger before 2.6 fails to sanitize first_name and last_name fields in the gym member TSV export endpoint, allowing any gym member to inject spreadsheet formulas. Attackers can inject formulas like =HYPERLINK to exfiltrate admin data or execute code wh...

  • EPSS 0.18%
  • Veröffentlicht 06.09.2026 12:17:16
  • Zuletzt bearbeitet 09.09.2026 14:17:22

wger before 2.6 (affected versions <= 2.5.0) contains an open redirect vulnerability in the trainer_login view (wger/core/views/user.py). After a trainer enters impersonation mode, the view redirects to the user-supplied 'next' GET parameter via Http...

  • EPSS 0.25%
  • Veröffentlicht 06.09.2026 12:17:16
  • Zuletzt bearbeitet 18.09.2026 18:17:18

wger before 2.5 fails to validate the maximum duration of routine date ranges, allowing authenticated users to create routines spanning arbitrarily long periods. Attackers can trigger the date_sequence computation via routine detail endpoints, forcin...

  • EPSS 0.22%
  • Veröffentlicht 06.09.2026 12:17:16
  • Zuletzt bearbeitet 08.09.2026 19:59:42

wger versions through master contain an incomplete authorization bypass in wger/core/views/user.py where three views retain the original gym-scope check using raw integer comparison instead of the is_same_gym() helper, allowing gym staff with gym=Non...

  • EPSS 0.17%
  • Veröffentlicht 30.08.2026 13:45:09
  • Zuletzt bearbeitet 31.08.2026 22:17:24

A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It ...