Stored XSS Vulnerability in wger Fitness Manager by wger-project
CVE-2026-40353

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
17 April 2026

What is CVE-2026-40353?

The wger Fitness Manager, an open-source application aimed at managing workouts and fitness routines, is susceptible to a vulnerability affecting versions 2.5 and earlier. The issue lies in the handling of the attribution_link property in the AbstractLicenseModel. Specifically, it fails to properly escape user-controlled license fields, allowing an authenticated user to insert a malicious license_author value. This value can contain JavaScript code, which is executed in the browsers of users who visit the ingredient page, leading to stored cross-site scripting (XSS) attacks. This vulnerability has been addressed in version 2.5, reinforcing the importance of regular updates and vigilant security practices.

Affected Version(s)

wger < 2.5

References

CVSS V4

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.