Stored XSS Vulnerability in wger Fitness Manager by wger-project
CVE-2026-40353
5.1MEDIUM
What is CVE-2026-40353?
The wger Fitness Manager, an open-source application aimed at managing workouts and fitness routines, is susceptible to a vulnerability affecting versions 2.5 and earlier. The issue lies in the handling of the attribution_link property in the AbstractLicenseModel. Specifically, it fails to properly escape user-controlled license fields, allowing an authenticated user to insert a malicious license_author value. This value can contain JavaScript code, which is executed in the browsers of users who visit the ingredient page, leading to stored cross-site scripting (XSS) attacks. This vulnerability has been addressed in version 2.5, reinforcing the importance of regular updates and vigilant security practices.
Affected Version(s)
wger < 2.5
