Labredescefetrj Wegia vulnerabilities
178 known vulnerabilities affecting labredescefetrj/wegia.
Total CVEs
178
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL38HIGH46MEDIUM93
Vulnerabilities
Page 7 of 9
CVE-2025-30366P4MEDIUMCVSS 5.4fixed in 3.2.82025-03-27
CVE-2025-30366 [MEDIUM] CWE-79 CVE-2025-30366: WeGIA is a Web manager for charitable institutions. Versions prior to 3.2.8 are vulnerable to stored
WeGIA is a Web manager for charitable institutions. Versions prior to 3.2.8 are vulnerable to stored cross-site scripting. This vulnerability allows unauthorized scripts to be executed within the user's browser context. Stored XSS is particularly critical, as the malicious code is permanently stored on the server and executed whenever a compromised p
nvd
CVE-2025-67496P4MEDIUMCVSS 5.4fixed in 3.5.52025-12-09
CVE-2025-67496 [MEDIUM] CWE-79 CVE-2025-67496: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Vers
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Versions 3.5.4 and below contain a Stored Cross-Site Scripting (XSS) vulnerability in the /WeGIA/html/geral/configurar_senhas.php endpoint. The application does not sanitize user-controlled data before rendering it inside the employee selection dropdown. T
nvd
CVE-2026-23725P4MEDIUMCVSS 5.4fixed in 3.6.22026-01-16
CVE-2026-23725 [MEDIUM] CWE-79 CVE-2026-23725: WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (X
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the html/pet/adotantes/cadastro_adotante.php and html/pet/adotantes/informacao_adotantes.php endpoint of the WeGIA application. The application does not sanitize user-controlled input before rendering it inside the A
nvd
CVE-2026-23724P4MEDIUMCVSS 5.4fixed in 3.6.22026-01-16
CVE-2026-23724 [MEDIUM] CWE-79 CVE-2026-23724: WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (X
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the html/atendido/cadastro_ocorrencia.php endpoint of the WeGIA application. The application does not sanitize user-controlled data before rendering it inside the “Atendido” selection dropdown. This vulnerability is
nvd
CVE-2025-22598P4MEDIUMCVSS 6.1fixed in 3.2.82025-01-10
CVE-2025-22598 [MEDIUM] CWE-79 CVE-2025-22598: WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerabilit
WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the cadastrarSocio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scripts are stored on the server and executed automatically wh
nvd
CVE-2025-22597P4MEDIUMCVSS 6.1fixed in 3.2.82025-01-10
CVE-2025-22597 [MEDIUM] CWE-79 CVE-2025-22597: WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerabilit
WeGIA is a web manager for charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the CobrancaController.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the local_recepcao parameter. The injected scripts are stored on the server and executed automaticall
nvd
CVE-2025-23030P4MEDIUMCVSS 6.1v3.4.02025-01-14
CVE-2025-23030 [MEDIUM] CWE-79 CVE-2025-23030: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `cadastro_funcionario.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `cpf` parameter. The application fails
nvd
CVE-2025-22615P4MEDIUMCVSS 6.1v3.4.02025-01-13
CVE-2025-22615 [MEDIUM] CWE-79 CVE-2025-22615: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `Cadastro_Atendido.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `cpf` parameter. The application fails to
nvd
CVE-2025-23034P4MEDIUMCVSS 6.1fixed in 3.2.62025-01-14
CVE-2025-23034 [MEDIUM] CWE-79 CVE-2025-23034: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `tags.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `msg_e` parameter. The application fails to validate an
nvd
CVE-2025-62597P4MEDIUMCVSS 6.1fixed in 3.5.12025-10-21
CVE-2025-62597 [MEDIUM] CWE-79 CVE-2025-62597: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prio
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the sql parameter. The vulnerab
nvd
CVE-2025-27417P4MEDIUMCVSS 6.1fixed in 3.2.162025-03-03
CVE-2025-27417 [MEDIUM] CWE-79 CVE-2025-27417: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A St
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the adicionar_status_atendido.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the status parameter. The injected scripts are sto
nvd
CVE-2025-27499P4MEDIUMCVSS 6.1fixed in 3.2.102025-03-03
CVE-2025-27499 [MEDIUM] CWE-79 CVE-2025-27499: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A St
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the processa_edicao_socio.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the socio_nome parameter. The injected scripts are sto
nvd
CVE-2025-22617P4MEDIUMCVSS 6.1fixed in 3.2.72025-01-13
CVE-2025-22617 [MEDIUM] CWE-79 CVE-2025-22617: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `editar_socio.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `socio` parameter. The application fails to val
nvd
CVE-2025-62358P4MEDIUMCVSS 6.1fixed in 3.5.12025-10-13
CVE-2025-62358 [MEDIUM] CWE-79 CVE-2025-62358: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prio
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.1, the log parameter in configuracao_geral.php is vulnerable to Reflected Cross-Site Scripting (XSS). An attacker can inject arbitrary JavaScript, which executes in the victim’s browser. This vulnerability is fixed in 3.5.1.
nvd
CVE-2025-22613P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-13
CVE-2025-22613 [MEDIUM] CWE-79 CVE-2025-22613: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `informacao_adicional.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `descricao` parameter. The injected scri
nvd
CVE-2025-22618P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-13
CVE-2025-22618 [MEDIUM] CWE-79 CVE-2025-22618: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cargo.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `cargo` parameter. The injected scripts are s
nvd
CVE-2025-23037P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-14
CVE-2025-23037 [MEDIUM] CWE-79 CVE-2025-23037: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `control.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `cargo` parameter. The injected scripts are stored on
nvd
CVE-2025-23032P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-14
CVE-2025-23032 [MEDIUM] CWE-79 CVE-2025-23032: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_escala.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `escala` parameter. The injected scripts are
nvd
CVE-2025-23035P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-14
CVE-2025-23035 [MEDIUM] CWE-79 CVE-2025-23035: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_tipo_quadro_horario.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `tipo` parameter. The injected
nvd
CVE-2025-23038P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-14
CVE-2025-23038 [MEDIUM] CWE-79 CVE-2025-23038: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `remuneracao.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `descricao` parameter. The injected scripts are s
nvd