Wger is a modestly represented, focused fitness and workout-management application whose vulnerability profile skews toward serious outcomes including critical-severity flaws. The recurring exposure centers on the workout manager product and reflects access-control and input-handling weaknesses characteristic of web applications, including authorization bypasses, cross-site scripting, cross-site request forgery, and improper authentication rate-limiting. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Wger over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-40474HIGH wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the GymConfigUpdateView declares permission_required = 'config.change_gymconfig' but inherits Wg | Apr 17, 2026 | 7.6 | 25 | NO | NO |
CVE-2022-2650CRITICAL Improper Restriction of Excessive Authentication Attempts in GitHub repository wger-project/wger prior to 2.2. | Nov 24, 2022 | 9.8 | 25 | NO | NO |
CVE-2023-38759HIGH Cross Site Request Forgery (CSRF) vulnerability in wger Project wger Workout Manager 2.2.0a3 allows a remote attacker to gain privileges via the user-management feature in the gym/ | Aug 8, 2023 | 8.8 | 24 | NO | NO |
CVE-2026-40353MEDIUM wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly interpolating | Apr 17, 2026 | 5.4 | 20 | NO | NO |
CVE-2026-27839MEDIUM wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, three `nutritional_values` action endpoints fetch objects via `Model.objects.get(pk=pk | Feb 26, 2026 | 4.3 | 19 | NO | NO |
CVE-2026-27835MEDIUM wger is a free, open-source workout and fitness manager. In versions up to and including 2.4, `RepetitionsConfigViewSet` and `MaxRepetitionsConfigViewSet` return all users' repetit | Feb 26, 2026 | 4.3 | 19 | NO | NO |
CVE-2023-38758MEDIUM Cross Site Scripting vulnerability in wger Project wger Workout Manager v.2.2.0a3 allows a remote attacker to gain privileges via the license_author field in the add-ingredient fun | Aug 8, 2023 | 5.4 | 19 | NO | NO |
wger is a free, open-source workout and fitness manager. Five routine detail action endpoints check a cache before calling `self.get_object()`. In versions up to and including 2.4, | Feb 26, 2026 | 3.5 | 15 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Wger.
Media articles that mention a CVE ID that affects a product developed by Wger — matched by CVE ID, not by vendor name.