CVE-2026-86257 | wger-project wger up to 2.5 TSV Export first_name/last_name injection (EUVD-2026-72113)
A vulnerability was found in wger-project wger up to 2.5 and classified as problematic. This vulnerability affects unknown code of the component TSV Export. Executing a manipulation of the argument first_name/last_name can lead to injection.
The identification of this vulnerability is CVE-2026-86257. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.