A flaw in wger-project wger up to 2.6.0-alpha2 allows for cross-site request forgery attacks via the reset_user_password function in wger/gym/views/gym.py. This issue can be exploited remotely, and users should apply the patch to prevent such attacks. The CVE record was published on 2026-08-30T14:17:02.627Z and has not been modified since then. The affected product is wger-project wger up to 2.6.0-alpha2. [truncated]
A vulnerability in wger, a free, open-source workout and fitness manager, allows a gym trainer to escalate their session to any higher-privileged account by chaining two calls to the trainer-login endpoint. This grants full gym administration capabilities. The vulnerability has been fixed in version 2.6. Users of wger versions prior to 2.6, particularly gym administrators and trainers, should be aware of [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-16T23:16:16.167Z and has not been modified since then. The vulnerability exists in wger Workout and Fitness Manager versions prior to 2.6, allowing any authenticated user to read another user's private workout session notes, exercise history, and training statistics. This issue has been fixed in ver [truncated]