Vulnerabilidades en wger-project
14 resultadosAnálisis Vexday
O wger-project apresenta 9 vulnerabilidades catalogadas, com 1 crítica e 3 descobertas nos últimos 90 dias, indicando risco moderado e ativo. Nenhuma vulnerabilidade está sob exploração documentada em ataques (KEV), reduzindo a ameaça imediata. A fraqueza dominante (CWE-639) sugere problemas de controle de autorização que merecem priorização na remediação.
CVE-2022-2650HIGHImproper Restriction of Excessive Authentication Attempts in wger-project/wgerEPSS 0.7%CVE-2026-43977HIGHwger IDOR: Authenticated Users Can Read Others' Private Workout Session Data via Template Routine APIEPSS 0.4%CVE-2026-43948CRITICALwger: cross-tenant password reset and plaintext disclosure via gym=None bypassEPSS 0.4%CVE-2026-43978HIGHwger: Privilege escalation via trainer-login session chaining allows gym trainers to impersonate gym managersEPSS 0.4%CVE-2026-40474HIGHwger has Broken Access Control in the Global Gym Configuration Update EndpointEPSS 0.3%CVE-2026-27839MEDIUMwger: IDOR in nutritional_values endpoints exposes private dietary data via direct ORM lookupEPSS 0.3%CVE-2026-27835MEDIUMwger: IDOR in RepetitionsConfig and MaxRepetitionsConfig API leak other users' workout dataEPSS 0.3%CVE-2026-86255HIGHwger before 2.5 Uncontrolled Resource Consumption via date_sequenceEPSS 0.2%CVE-2026-27838LOWwger: IDOR via user-unscoped cache keys on routine API actions exposes workout dataEPSS 0.2%CVE-2026-86254MEDIUMwger Incomplete Authorization Fix Cross-Tenant Account DeletionEPSS 0.2%CVE-2026-40353MEDIUMwger: Stored XSS via Unescaped License Attribution FieldsEPSS 0.2%CVE-2026-86256MEDIUMwger before 2.6 Open Redirect via trainer-login next parameterEPSS 0.2%CVE-2026-82544MEDIUMwger-project wger Password Reset gym.py reset_user_password cross-site request forgeryEPSS 0.2%CVE-2026-86257MEDIUMwger before 2.6 CSV Formula Injection via member exportEPSS 0.2%