pkg:PyPI/wger
13 total CVEsCRITICAL2HIGH5MEDIUM5LOW1
✅ Check your installed version
All known vulnerabilities
- CRITICAL9.9CVE-2026-43948wger: cross-tenant password reset and plaintext disclosure via gym=None bypassfrom 0, < 2.6
- from 0, < 2.2
- from 0, <= 2.2.0a3
- from 0
- HIGH8.1CVE-2026-43978wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym managerfrom 0, <= 2.5
- from 0, <= 2.1
- HIGH7.5CVE-2026-43977wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine APIfrom 0, <= 2.5
- from 0, <= 2.4
- from 0
- from 0, <= 2.2.0a3
- MEDIUM4.3CVE-2026-27839wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookupfrom 0, <= 2.1
- MEDIUM4.3CVE-2026-27835wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout datafrom 0, <= 2.1
- LOW3.1CVE-2026-27838wger: IDOR via user-unscoped cache keys on routine API actions exposes workout datafrom 0, <= 2.1