Labredescefetrj Wegia vulnerabilities
178 known vulnerabilities affecting labredescefetrj/wegia.
Total CVEs
178
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL38HIGH46MEDIUM93
Vulnerabilities
Page 2 of 9
CVE-2025-53823P2HIGHCVSS 8.8fixed in 3.4.52025-07-14
CVE-2025-53823 [HIGH] CWE-89 CVE-2025-53823: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection vulnerability in the endpoint `/WeGIA/html/socio/sistema/processa_deletar_socio.php`, in the `id_socio` parameter. This vulnerability allows the execution of arbitrary SQL commands, which can compromise t
nvd
CVE-2026-33134P2HIGHCVSS 8.8fixed in 3.6.62026-03-20
CVE-2026-33134 [HIGH] CWE-89 CVE-2026-33134: WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticate
WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticated attacker to inject arbitrary SQL commands via the id_produto GET parameter, leading to full database compromise. In the script /htm
nvd
CVE-2026-35395P2HIGHCVSS 8.8fixed in 3.6.92026-04-06
CVE-2026-35395 [HIGH] CWE-89 CVE-2026-35395: WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para inst
WeGIA is a Web manager for charitable institutions. Prior to 3.6.9, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in dao/memorando/DespachoDAO.php. The id_memorando parameter is extracted from $_REQUEST without validation and directly interpolated into SQL queries, allowing any authenticated user to exec
nvd
CVE-2026-31896P3CRITICALCVSS 9.8fixed in 3.6.62026-03-11
CVE-2026-31896 [CRITICAL] CWE-89 CVE-2026-31896: WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then directly concatenates these variables into a SQL query executed via PDO::query. This allows an authent
nvd
CVE-2025-55168P2CRITICALCVSS 9.8fixed in 3.4.82025-08-12
CVE-2025-55168 [CRITICAL] CWE-89 CVE-2025-55168: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a SQL Injection vulnerability was identified in the /html/saude/aplicar_medicamento.php endpoint, specifically in the id_fichamedica parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compro
nvd
CVE-2025-23218P3CRITICALCVSS 9.8fixed in 3.2.102025-01-20
CVE-2025-23218 [CRITICAL] CWE-89 CVE-2025-23218: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_especie.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in the database, allowing unauthorized access to sen
nvd
CVE-2025-23219P3CRITICALCVSS 9.8fixed in 3.2.102025-01-20
CVE-2025-23219 [CRITICAL] CWE-89 CVE-2025-23219: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_cor.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in the database, allowing unauthorized access to sensiti
nvd
CVE-2025-23220P3CRITICALCVSS 9.8fixed in 3.2.102025-01-20
CVE-2025-23220 [CRITICAL] CWE-89 CVE-2025-23220: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in the WeGIA application, specifically in the adicionar_raca.php endpoint. This vulnerability allows attackers to execute arbitrary SQL commands in the database, allowing unauthorized access to sensit
nvd
CVE-2025-26608P3CRITICALCVSS 9.8fixed in 3.2.132025-02-18
CVE-2025-26608 [CRITICAL] CWE-89 CVE-2025-26608: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQ
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `dependente_docdependente.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorized access to sensitive information. This issue
nvd
CVE-2025-26607P3CRITICALCVSS 9.8fixed in 3.2.132025-02-18
CVE-2025-26607 [CRITICAL] CWE-89 CVE-2025-26607: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQ
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `documento_excluir.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorized access to sensitive information. This issue has be
nvd
CVE-2025-26606P3CRITICALCVSS 9.8fixed in 3.2.132025-02-18
CVE-2025-26606 [CRITICAL] CWE-89 CVE-2025-26606: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQ
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `informacao_adicional.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorized access to sensitive information. This issue has
nvd
CVE-2025-24957P3CRITICALCVSS 9.8fixed in 3.2.122025-02-03
CVE-2025-24957 [CRITICAL] CWE-89 CVE-2025-24957: WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in
WeGIA is a Web Manager for Charitable Institutions. A SQL Injection vulnerability was discovered in the WeGIA application, `get_detalhes_socio.php` endpoint. This vulnerability could allow an authorized attacker to execute arbitrary SQL queries, allowing access to or deletion of sensitive information. This issue has been addressed in version 3.2.12
nvd
CVE-2025-26611P3CRITICALCVSS 9.8fixed in 3.2.132025-02-18
CVE-2025-26611 [CRITICAL] CWE-89 CVE-2025-26611: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQ
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `remover_produto.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorized access to sensitive information. This issue has been
nvd
CVE-2025-53527P2CRITICALCVSS 9.8v>= 3.3.3, < 3.4.12025-07-07
CVE-2025-53527 [CRITICAL] CWE-89 CVE-2025-53527: WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability w
WeGIA is a web manager for charitable institutions. A Time-Based Blind SQL Injection vulnerability was discovered in the almox parameter of the /controle/relatorio_geracao.php endpoint. This issue allows attacker to inject arbitrary SQL queries, potentially leading to unauthorized data access or further exploitation depending on database configurat
nvd
CVE-2025-61605P2CRITICALCVSS 9.8fixed in 3.5.02025-10-02
CVE-2025-61605 [CRITICAL] CWE-89 CVE-2025-61605: WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and bel
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain an SQL Injection vulnerability which was identified in the /pet/profile_pet.php endpoint, specifically in the id_pet parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integr
nvd
CVE-2026-54671P3HIGHCVSS 8.8fixed in 3.8.52026-09-17
CVE-2026-54671 [HIGH] CWE-639 CVE-2026-54671: WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an
WeGIA is a web manager for charitable institutions. Prior to 3.8.5, WeGIA maps InternoControle to an empty resource array in web/controle/control.php, and verificarPermissao in web/dao/MiddlewareDAO.php treats that empty array as unconditional access for every authenticated user. The methods in web/controle/InternoControle.php, including listarUm, alt
nvd
CVE-2025-54062P2HIGHCVSS 8.8fixed in 3.4.62025-07-17
CVE-2025-54062 [HIGH] CWE-89 CVE-2025-54062: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `/html/funcionario/profile_dependente.php` endpoint, specifically in the `id_dependente` parameter. This vulnerability allows attackers to execute arbitrary SQL commands,
nvd
CVE-2026-40285P3HIGHCVSS 8.8fixed in 3.6.102026-04-17
CVE-2026-40285 [HIGH] CWE-89 CVE-2026-40285: WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection
WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter overwrites the session-stored user identity via extract($_REQUEST) in DespachoControle::verificarDespacho(), and the attacker-controlled value is then interpolated directly in
nvd
CVE-2025-27096P3CRITICALCVSS 9.8fixed in 3.2.142025-02-20
CVE-2025-27096 [CRITICAL] CWE-89 CVE-2025-27096: WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnera
WeGIA is a Web Manager for Institutions with a focus on Portuguese language. A SQL Injection vulnerability was discovered in the WeGIA application, personalizacao_upload.php endpoint. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. This issue has been addressed in version 3
nvd
CVE-2025-26612P3CRITICALCVSS 9.8fixed in 3.2.132025-02-18
CVE-2025-26612 [CRITICAL] CWE-89 CVE-2025-26612: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQ
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the WeGIA application, `adicionar_almoxarife.php` endpoint. This vulnerability could allow an attacker to execute arbitrary SQL queries, allowing unauthorized access to sensitive information. This issue has
nvd