Technology · PyPI
wger (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 18 vulnerabilities in wger (PyPI): 0 in the last 7 days and 11 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-86257, was published on 6 September 2026.
- Last 7 days
- 0
- Last 90 days
- 11
- Critical, all time
- 1
- Exploited in the wild
- 0
About wger (PyPI)
A fitness and workout management application for tracking exercises and nutrition.
Latest wger (PyPI) vulnerabilities
- CVE-2026-86257: wger CSV/TSV formula injection in gym member exportmediumCVSS 5.4EPSS 0.3%
- CVE-2026-86256: wger trainer_login open redirect in next parametermediumCVSS 5.4EPSS 0.2%
- CVE-2026-86255: wger Uncontrolled Resource Consumption in date_sequencemediumCVSS 6.5EPSS 0.4%
- CVE-2026-86254: wger incomplete authorization bypass in user management viewsmediumCVSS 6.8EPSS 0.4%
- CVE-2026-82544: Wger password reset cross-site request forgerymediumCVSS 4.3EPSS 0.2%
- CVE-2026-43978: wger privilege escalation in trainer-login session chaininghighCVSS 8.1EPSS 0.4%
- CVE-2026-43977: wger IDOR in RoutineViewSet logs and stats endpointshighCVSS 7.5EPSS 0.4%
- CVE-2026-27839: PYSEC-2026-3422 - wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookuplowCVSS 3.1EPSS 0.3%
- CVE-2026-27838: PYSEC-2026-3418 - wger: IDOR via user-unscoped cache keys on routine API actions exposes workout datalowCVSS 3.1EPSS 0.3%
- CVE-2026-27835: PYSEC-2026-3423 - wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout datalowCVSS 3.1EPSS 0.3%
- CVE-2022-2650: PYSEC-2026-573 - wger vulnerable to brute force attemptslowCVSS 3.1EPSS 0.7%
- wger cross-tenant account deletion and deactivation in core user viewshighCVSS 8.5
- wger uncontrolled resource consumption in workout routine date sequencemediumCVSS 6.5
- CVE-2026-43948: wger Incorrect Authorization in password reset and user edit viewscriticalCVSS 9.9EPSS 0.4%
- CVE-2026-40353: wger has Stored XSS via Unescaped License Attribution FieldsmediumCVSS 5.4EPSS 0.3%
- CVE-2026-40474: wger has Broken Access Control in Global Gym Configuration Update EndpointhighCVSS 7.6EPSS 0.4%
- CVE-2023-38758: PYSEC-2023-143 - Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote…lowCVSS 3.1EPSS 0.6%
- CVE-2023-38759: PYSEC-2023-144 - Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a…lowCVSS 3.1EPSS 0.4%
Most severe wger (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-43948: wger Incorrect Authorization in password reset and user edit viewscriticalCVSS 9.9EPSS 0.4%
- wger cross-tenant account deletion and deactivation in core user viewshighCVSS 8.5
- CVE-2026-43978: wger privilege escalation in trainer-login session chaininghighCVSS 8.1EPSS 0.4%
- CVE-2026-40474: wger has Broken Access Control in Global Gym Configuration Update EndpointhighCVSS 7.6EPSS 0.4%
- CVE-2026-43977: wger IDOR in RoutineViewSet logs and stats endpointshighCVSS 7.5EPSS 0.4%
- CVE-2026-86254: wger incomplete authorization bypass in user management viewsmediumCVSS 6.8EPSS 0.4%
- CVE-2026-86255: wger Uncontrolled Resource Consumption in date_sequencemediumCVSS 6.5EPSS 0.4%
- wger uncontrolled resource consumption in workout routine date sequencemediumCVSS 6.5
- CVE-2026-86257: wger CSV/TSV formula injection in gym member exportmediumCVSS 5.4EPSS 0.3%
- CVE-2026-40353: wger has Stored XSS via Unescaped License Attribution FieldsmediumCVSS 5.4EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 1 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 5 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 1 | 0 | |
| 31 Aug 2026 | 4 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/wger.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "wger (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/wger, 26 September 2026.