CVE-2026-82544
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/view
CVSS
4.3
Medium
EPSS
—
KEV
—
Exploit Today
0
0-100
Published: Aug 30, 2026 · Last modified: Aug 30, 2026 · CWE-352 · CWE-862
Not enough EPSS history yet.
A flaw has been found in wger-project wger up to 2.6.0-alpha2. This issue affects the function reset_user_password of the file wger/gym/views/gym.py of the component Password Reset. Executing a manipulation can lead to cross-site request forgery. It is possible to launch the attack remotely. This patch is called 3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314. It is advisable to implement a patch to correct this issue.
- github.comhttps://github.com/wger-project/wger/
- github.comhttps://github.com/wger-project/wger/commit/3c6ce4b7f3eeafeb35318c6c4e82b1a3fd28b314
- github.comhttps://github.com/wger-project/wger/issues/2380
- github.comhttps://github.com/wger-project/wger/pull/2415
- vuldb.comhttps://vuldb.com/cve/CVE-2026-82544
- vuldb.comhttps://vuldb.com/submit/891417
- vuldb.comhttps://vuldb.com/vuln/397061
- vuldb.comhttps://vuldb.com/vuln/397061/cti
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-826476.1 MED—
——0WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends emails with attacker-controlled subject and body to arbitrary recipients, passing SPF/DKIM/DMARC validation for phishing and brand impersonation attacks.6hCVE-2026-826334.3 MED—
——0Dolibarr versions 10.0.0 before 24.0.0 fail to perform per-object authorization checks in the Users::getGroups REST API endpoint, allowing authenticated users to retrieve group memberships of other users. Attackers can call GET /users/{id}/groups with arbitrary user identifiers to access group names, entity associations, and private notes across tenant boundaries.8hCVE-2026-824758.1 HIG16.9%
——5iFlytek astron-agent through 1.1.1 contains an authorization bypass vulnerability in the copyFlow endpoint that fails to validate workflow ownership. Authenticated attackers can enumerate workflow identifiers and overwrite other tenants' workflows or copy private workflows to read their definitions.1dCVE-2026-824684.7 MED2.2%
——1Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content type validation. Attackers can craft cross-origin form posts with content types containing application/json substrings to bypass CSRF token validation and force victims to authenticate to attacker-controlled accounts.1dCVE-2026-813464.3 MED4.7%
——1The Frontend Admin by DynamiApps WordPress plugin before 3.29.11 does not perform a capability check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to delete arbitrary membership plans.20hCVE-2026-194305.3 MED9.0%
——3The Catfolders Document Gallery Pro WordPress plugin before 2.0.7 does not authorise some of its REST API routes, and the token identifying the requested content is forgeable client side, allowing unauthenticated users to list and download the contents of folders that were never published on the site.20h