Labredescefetrj Wegia vulnerabilities
178 known vulnerabilities affecting labredescefetrj/wegia.
Total CVEs
178
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL38HIGH46MEDIUM93
Vulnerabilities
Page 4 of 9
CVE-2025-54060P3HIGHCVSS 8.8fixed in 3.4.62025-07-17
CVE-2025-54060 [HIGH] CWE-89 CVE-2025-54060: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.6 in the `idatendido_familiares` parameter of the `/html/funcionario/dependente_editarInfoPessoal.php` endpoint. This vulnerability allows attacker to manipulate SQL queries and a
nvd
CVE-2025-53946P3HIGHCVSS 8.8fixed in 3.4.52025-07-17
CVE-2025-53946 [HIGH] CWE-89 CVE-2025-53946: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.4.5 in the `id_funcionario` parameter of the `/html/saude/profile_paciente.php` endpoint. This vulnerability allows attacker to manipulate SQL queries and access sensitive database
nvd
CVE-2025-59939P3HIGHCVSS 8.8fixed in 3.5.02025-09-27
CVE-2025-59939 [HIGH] CWE-89 CVE-2025-59939: WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to S
WeGIA is a Web manager for charitable institutions. Prior to version 3.5.0, WeGIA is vulnerable to SQL Injection attacks in the control.php endpoint with the following parameters: nomeClasse=ProdutoControle&metodo=excluir&id_produto=[malicious command]. It is necessary to apply prepared statements methods, sanitization, and validations on theid_produto
nvd
CVE-2025-52474P3CRITICALCVSS 9.8fixed in 3.4.22025-06-19
CVE-2025-52474 [CRITICAL] CWE-89 CVE-2025-52474: WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerab
WeGIA is a web manager for charitable institutions. Prior to version 3.4.2, a SQL Injection vulnerability was identified in the id parameter of the /WeGIA/controle/control.php endpoint. This vulnerability allows attacker to manipulate SQL queries and access sensitive database information, such as table names and sensitive data. This issue has been
nvd
CVE-2025-67501P3HIGHCVSS 8.8fixed in 3.5.52025-12-10
CVE-2025-67501 [HIGH] CWE-89 CVE-2025-67501: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Vers
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain an SQL Injection vulnerability in the /html/matPat/editar_categoria.php endpoint. The application fails to properly validate and sanitize user inputs in the id_categoria parameter, which allows attackers to inject malicious S
nvd
CVE-2025-58453P3HIGHCVSS 8.2fixed in 3.4.112025-09-08
CVE-2025-58453 [HIGH] CWE-89 CVE-2025-58453: WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior in the endpoint /WeGIA/html/memorando/exibe_anexo.php, in the id_anexo parameter. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3.4.11 co
nvd
CVE-2025-58454P3HIGHCVSS 8.2fixed in 3.4.112025-09-08
CVE-2025-58454 [HIGH] CWE-89 CVE-2025-58454: WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in
WeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in WeGIA versions 3.4.10 and prior inthe endpoint /WeGIA/html/memorando/listar_despachos.php, in the id_memorando parameter. This vulnerability allow an authorized attacker to execute arbitrary SQL queries, allowing access to sensitive information. Version 3
nvd
CVE-2026-76633P3HIGHCVSS 8.1fixed in 3.9.22026-08-20
CVE-2026-76633 [HIGH] CWE-620 CVE-2026-76633: WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that a
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir
nvd
CVE-2025-53938P3HIGHCVSS 7.5fixed in 3.4.52025-07-16
CVE-2025-53938 [HIGH] CWE-306 CVE-2025-53938: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. An Authentication Bypass vulnerability was identified in the `/dao/verificar_recursos_cargo.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows unauthenticated users to access protected application functionaliti
nvd
CVE-2026-33133P3HIGHCVSS 7.2v>= 3.6.5, < 3.6.72026-03-20
CVE-2026-33133 [HIGH] CWE-89 CVE-2026-33133: WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB()
WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator accounts, modify existing passwords, or execute any databas
nvd
CVE-2025-61665P3HIGHCVSS 7.5fixed in 3.5.02025-10-02
CVE-2025-61665 [HIGH] CWE-200 CVE-2025-61665: WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and bel
WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers to directly access sensitive personal and financial information of members without requiring auth
nvd
CVE-2026-23723P3HIGHCVSS 7.2fixed in 3.6.22026-01-16
CVE-2026-23723 [HIGH] CWE-89 CVE-2026-23723: WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection v
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, an authenticated SQL Injection vulnerability was identified in the Atendido_ocorrenciaControle endpoint via the id_memorando parameter. This flaw allows for full database exfiltration, exposure of sensitive PII, and potential arbitrary file reads in misconfigured environments. This vul
nvd
CVE-2026-31894P3HIGHCVSS 7.5v>= 3.6.5, < 3.6.62026-03-11
CVE-2026-31894 [HIGH] CWE-59 CVE-2026-31894: WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts ta
WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class, then uses glob() and file_get_contents() to read SQL files from the extracted contents. Neither the extraction nor the file reading validates whether archive members are symbolic links. T
nvd
CVE-2025-26615P3HIGHCVSS 7.5fixed in 3.2.142025-02-18
CVE-2025-26615 [HIGH] CWE-22 CVE-2025-26615: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Pa
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive information stored in `config.php`. `config.php` contains information that co
nvd
CVE-2025-26616P3HIGHCVSS 7.5fixed in 3.2.142025-02-18
CVE-2025-26616 [HIGH] CWE-22 CVE-2025-26616: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Pa
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `exportar_dump.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive information stored in `config.php`. `config.php` contains information th
nvd
CVE-2025-55171P3HIGHCVSS 7.5fixed in 3.4.82025-08-12
CVE-2025-55171 [HIGH] CWE-287 CVE-2025-55171: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, the application does not check authentication at endpoint /html/personalizacao_remover.php allowing anonymous attacker (without login) to delete any Image files at endpoint /html/personalizacao_remover.php by defining imagem
nvd
CVE-2026-40286P3HIGHCVSS 7.5fixed in 3.6.102026-04-17
CVE-2026-40286 [HIGH] CWE-79 CVE-2026-40286: WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) function. By injecting a payload into the 'Member Name' (Nome Sócio) field, the script is persistently stored in the database. Consequently, the payload is execu
nvd
CVE-2026-76634P3MEDIUMCVSS 6.5fixed in 3.9.22026-08-20
CVE-2026-76634 [MEDIUM] CWE-639 CVE-2026-76634: WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profil
WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to r
nvd
CVE-2025-27419P3HIGHCVSS 7.5fixed in 3.2.162025-03-03
CVE-2025-27419 [HIGH] CWE-770 CVE-2025-27419: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A De
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Denial of Service (DoS) vulnerability exists in WeGIA. This vulnerability allows any unauthenticated user to cause the server to become unresponsive by performing aggressive spidering. The vulnerability is caused by recursive crawling of dynamically gener
nvd
CVE-2025-53531P3HIGHCVSS 7.5fixed in 3.3.02025-07-07
CVE-2025-53531 [HIGH] CWE-770 CVE-2025-53531: WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows
WeGIA is a web manager for charitable institutions. The Wegia server has a vulnerability that allows excessively long HTTP GET requests to a specific URL. This issue arises from the lack of validation for the length of the fid parameter. Tests confirmed that the server processes URLs up to 8,142 characters, resulting in high resource consumption, elev
nvd