CVE-2026-33136
- EPSS 0.21%
- Veröffentlicht 20.03.2026 10:41:05
- Zuletzt bearbeitet 20.03.2026 19:23:40
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the scc...
CVE-2026-33135
- EPSS 0.22%
- Veröffentlicht 20.03.2026 10:38:44
- Zuletzt bearbeitet 20.03.2026 19:25:45
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which...
CVE-2026-33134
- EPSS 0.3%
- Veröffentlicht 20.03.2026 10:35:43
- Zuletzt bearbeitet 20.03.2026 19:26:28
WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticated attacker to inject arbitrar...
CVE-2026-33133
- EPSS 0.4%
- Veröffentlicht 20.03.2026 10:31:38
- Zuletzt bearbeitet 20.03.2026 19:29:20
WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary S...
CVE-2026-31896
- EPSS 0.35%
- Veröffentlicht 11.03.2026 19:10:32
- Zuletzt bearbeitet 13.03.2026 20:05:49
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then di...
CVE-2026-31895
- EPSS 0.39%
- Veröffentlicht 11.03.2026 19:08:18
- Zuletzt bearbeitet 13.03.2026 20:06:31
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_produto.php. The id_produto parameter from $_GET is di...
CVE-2026-31894
- EPSS 0.41%
- Veröffentlicht 11.03.2026 19:05:51
- Zuletzt bearbeitet 13.03.2026 20:22:24
WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted conte...
CVE-2026-28411
- EPSS 0.59%
- Veröffentlicht 27.02.2026 21:52:05
- Zuletzt bearbeitet 03.03.2026 17:56:18
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnera...
CVE-2026-28409
- EPSS 3.32%
- Veröffentlicht 27.02.2026 21:50:21
- Zuletzt bearbeitet 03.03.2026 18:20:07
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can b...
CVE-2026-28408
- EPSS 0.51%
- Veröffentlicht 27.02.2026 21:49:14
- Zuletzt bearbeitet 03.03.2026 18:22:19
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks. A maliciou...