VDB
KO

package

PyPI / wger

pkg:pypi/wger

HIGH 8.5 PyPI
GHSA-mw8f-w6p8-xrf4

wger: cross-tenant account deletion / deactivation / activation by gym.manage_gym + gym=None

Modified: 5/20/2026

MEDIUM 6.5 PyPI
GHSA-v25j-wqcw-fvhj

wger has an Uncontrolled Resource Consumption issue

Modified: 5/13/2026

MEDIUM 5.4 PyPI
GHSA-vqv8-j3mj-wjxj

wger: trainer_login open redirect - ?next= parameter not validated against host

Modified: 5/6/2026

HIGH 7.4 PyPI
GHSA-xq9m-hmp9-fw87

wger: CSV/TSV formula injection in gym member export (first_name/last_name)

Modified: 5/6/2026