
CVE-2026-40353 wger is a free, open-source workout and fitness manager. In versions 2.5 and below, the attribution_link property in AbstractLicenseModel constructs HTML by directly … https://www.cve.org/CVERecord?id=CVE-2026-40353
Post summary
The text announces CVE-2026-40353, noting that wger versions ≤2.5 build HTML via the attribution_link property directly, indicating a possible cross‑site scripting flaw. No PoC, exploit code, or active exploitation details are provided.

