CVE-2026-33135
- EPSS 0.03%
- Veröffentlicht 20.03.2026 10:38:44
- Zuletzt bearbeitet 20.03.2026 19:25:45
WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the novo_memorandoo.php endpoint. An attacker can inject arbitrary JavaScript into the sccs GET parameter, which...
CVE-2026-33134
- EPSS 0.03%
- Veröffentlicht 20.03.2026 10:35:43
- Zuletzt bearbeitet 20.03.2026 19:26:28
WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticated attacker to inject arbitrar...
CVE-2026-33133
- EPSS 0.06%
- Veröffentlicht 20.03.2026 10:31:38
- Zuletzt bearbeitet 20.03.2026 19:29:20
WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary S...
CVE-2026-31896
- EPSS 0.04%
- Veröffentlicht 11.03.2026 19:10:32
- Zuletzt bearbeitet 13.03.2026 20:05:49
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then di...
CVE-2026-31895
- EPSS 0.04%
- Veröffentlicht 11.03.2026 19:08:18
- Zuletzt bearbeitet 13.03.2026 20:06:31
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_produto.php. The id_produto parameter from $_GET is di...
CVE-2026-31894
- EPSS 0.07%
- Veröffentlicht 11.03.2026 19:05:51
- Zuletzt bearbeitet 13.03.2026 20:22:24
WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted conte...
CVE-2026-28411
- EPSS 0.83%
- Veröffentlicht 27.02.2026 21:52:05
- Zuletzt bearbeitet 03.03.2026 17:56:18
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated attacker to overwrite local variables in multiple PHP scripts. This vulnera...
CVE-2026-28409
- EPSS 0.46%
- Veröffentlicht 27.02.2026 21:50:21
- Zuletzt bearbeitet 03.03.2026 18:20:07
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, a critical Remote Code Execution (RCE) vulnerability exists in the WeGIA application's database restoration functionality. An attacker with administrative access (which can b...
CVE-2026-28408
- EPSS 0.09%
- Veröffentlicht 27.02.2026 21:49:14
- Zuletzt bearbeitet 03.03.2026 18:22:19
WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, the script in adicionar_tipo_docs_atendido.php does not go through the project's central controller and does not have its own authentication and permission checks. A maliciou...
CVE-2026-23731
- EPSS 0.02%
- Veröffentlicht 16.01.2026 19:50:16
- Zuletzt bearbeitet 30.01.2026 18:30:32
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, The web application is vulnerable to clickjacking attacks. The WeGIA application does not send any defensive HTTP headers related to framing protection. In particular, X-Frame-Option...