wger records
8 published records for vendor wger.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 37.5%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-639 Authorization Bypass Through User-Controlled Key3
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-307 Improper Restriction of Excessive Authentication Attempts1
- CWE-352 Cross-Site Request Forgery (CSRF)1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-2650No exploit | Improper Restriction of Excessive Authentication Attempts in wger-project/wgerwger · wger · CWE-307 | Critical9.8 | — | 0.7% | Nov 24, 2022 |
35Monitor | CVE-2023-38759No exploit | Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges viawger · workout manager · CWE-352 | High8.8 | — | 0.4% | Aug 8, 2023 |
30Monitor | CVE-2026-40474No exploit | wger has Broken Access Control in the Global Gym Configuration Update Endpointwger · wger · CWE-284 | High7.6 | — | 0.4% | Apr 17, 2026 |
21Monitor | CVE-2023-38758No exploit | Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the licenswger · workout manager · CWE-79 | Medium5.4 | — | 0.6% | Aug 8, 2023 |
20Monitor | CVE-2026-40353No exploit | wger: Stored XSS via Unescaped License Attribution Fieldswger · wger · CWE-79 | Medium5.1 | — | 0.2% | Apr 17, 2026 |
17Monitor | CVE-2026-27839No exploit | wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookupwger · wger · CWE-639 | Medium4.3 | — | 0.3% | Feb 26, 2026 |
17Monitor | CVE-2026-27835No exploit | wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout datawger · wger · CWE-639 | Medium4.3 | — | 0.3% | Feb 26, 2026 |
14Monitor | CVE-2026-27838No exploit | wger: IDOR via user-unscoped cache keys on routine API actions exposes workout datawger · wger · CWE-639 | Low3.5 | — | 0.3% | Feb 26, 2026 |
- CVE-2022-265039Monitor
Improper Restriction of Excessive Authentication Attempts in wger-project/wger
CriticalCVSS 9.8No exploitEPSS 1%wger · wgerNov 24, 2022
- CVE-2023-3875935Monitor
Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via
HighCVSS 8.8No exploitEPSS 0%wger · workout managerAug 8, 2023
- CVE-2026-4047430Monitor
wger has Broken Access Control in the Global Gym Configuration Update Endpoint
HighCVSS 7.6No exploitEPSS 0%wger · wgerApr 17, 2026
- CVE-2023-3875821Monitor
Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the licens
MediumCVSS 5.4No exploitEPSS 1%wger · workout managerAug 8, 2023
- CVE-2026-4035320Monitor
wger: Stored XSS via Unescaped License Attribution Fields
MediumCVSS 5.1No exploitEPSS 0%wger · wgerApr 17, 2026
- CVE-2026-2783917Monitor
wger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookup
MediumCVSS 4.3No exploitEPSS 0%wger · wgerFeb 26, 2026
- CVE-2026-2783517Monitor
wger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout data
MediumCVSS 4.3No exploitEPSS 0%wger · wgerFeb 26, 2026
- CVE-2026-2783814Monitor
wger: IDOR via user-unscoped cache keys on routine API actions exposes workout data
LowCVSS 3.5No exploitEPSS 0%wger · wgerFeb 26, 2026