cbcvebase.

Labredescefetrj Wegia vulnerabilities

178 known vulnerabilities affecting labredescefetrj/wegia.

Total CVEs
178
CISA KEV
0
Public exploits
4
Exploited in wild
1
Severity breakdown
CRITICAL38HIGH46MEDIUM93

Vulnerabilities

Page 8 of 9
CVE-2025-23033P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-14
CVE-2025-23033 [MEDIUM] CWE-79 CVE-2025-23033: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_situacao.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `situacao` parameter. The injected scripts
nvd
CVE-2025-23031P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-14
CVE-2025-23031 [MEDIUM] CWE-79 CVE-2025-23031: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_alergia.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `nome` parameter. The injected scripts are
nvd
CVE-2025-22614P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-13
CVE-2025-22614 [MEDIUM] CWE-79 CVE-2025-22614: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `dependente_editarInfoPessoal.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `nome` and `SobrenomeForm`parame
nvd
CVE-2025-22616P4MEDIUMCVSS 5.4fixed in 3.2.62025-01-13
CVE-2025-22616 [MEDIUM] CWE-79 CVE-2025-22616: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `dependente_parentesco_adicionar.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the `descricao` parameter. The in
nvd
CVE-2025-53930P4MEDIUMCVSS 5.4fixed in 3.4.52025-07-16
CVE-2025-53930 [MEDIUM] CWE-79 CVE-2025-53930: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_especie.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `especie` parameter.
nvd
CVE-2025-53929P4MEDIUMCVSS 5.4fixed in 3.4.52025-07-16
CVE-2025-53929 [MEDIUM] CWE-79 CVE-2025-53929: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cor.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `cor` parameter. The inj
nvd
CVE-2025-53931P4MEDIUMCVSS 5.4fixed in 3.4.52025-07-16
CVE-2025-53931 [MEDIUM] CWE-79 CVE-2025-53931: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_raca.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `raca` parameter. The i
nvd
CVE-2025-53933P4MEDIUMCVSS 5.4fixed in 3.4.52025-07-16
CVE-2025-53933 [MEDIUM] CWE-79 CVE-2025-53933: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_enfermidade.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `nome` parameter
nvd
CVE-2025-53934P4MEDIUMCVSS 5.4fixed in 3.4.52025-07-16
CVE-2025-53934 [MEDIUM] CWE-79 CVE-2025-53934: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `control.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `descricao_emergencia` paramet
nvd
CVE-2025-27418P4MEDIUMCVSS 5.4fixed in 3.2.162025-03-03
CVE-2025-27418 [MEDIUM] CWE-79 CVE-2025-27418: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A St WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the adicionar_tipo_atendido.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts into the tipo parameter. The injected scripts are stored
nvd
CVE-2025-22600P4MEDIUMCVSS 6.5fixed in 3.2.82025-01-10
CVE-2025-22600 [MEDIUM] CWE-79 CVE-2025-22600: WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerabi WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the configuracao_doacao.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the avulso parameter. This vulnerability is fixed in 3.2.8.
nvd
CVE-2025-22599P4MEDIUMCVSS 6.5fixed in 3.2.82025-01-10
CVE-2025-22599 [MEDIUM] CWE-79 CVE-2025-22599: WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerabi WeGIA is a web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the home.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the msg_c parameter. This vulnerability is fixed in 3.2.8.
nvd
CVE-2025-22619P4MEDIUMCVSS 6.1fixed in 3.2.62025-01-13
CVE-2025-22619 [MEDIUM] CWE-79 CVE-2025-22619: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `editar_permissoes.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `msg_c` parameter. The application fails t
nvd
CVE-2025-62598P4MEDIUMCVSS 6.1fixed in 3.5.12025-10-21
CVE-2025-62598 [MEDIUM] CWE-79 CVE-2025-62598: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prio WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to version 3.5.1, a reflected cross-site scripting (XSS) vulnerability was identified in the editar_info_pessoal.php endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the action parameter. The vulne
nvd
CVE-2025-54078P4MEDIUMCVSS 6.1fixed in 3.4.62025-07-18
CVE-2025-54078 [MEDIUM] CWE-79 CVE-2025-54078: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.4.6 in the `personalizacao_imagem.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `err` param
nvd
CVE-2025-54077P4MEDIUMCVSS 6.1fixed in 3.4.62025-07-18
CVE-2025-54077 [MEDIUM] CWE-79 CVE-2025-54077: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.4.6 in the `personalizacao.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `err` parameter. V
nvd
CVE-2025-54076P4MEDIUMCVSS 6.1fixed in 3.4.62025-07-18
CVE-2025-54076 [MEDIUM] CWE-79 CVE-2025-54076: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in versions prior to 3.4.6 in the `pre_cadastro_atendido.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `msg_e` par
nvd
CVE-2025-62359P4MEDIUMCVSS 6.1fixed in 3.5.02025-10-13
CVE-2025-62359 [MEDIUM] CWE-79 CVE-2025-62359: WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prio WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. Prior to 3.5.0, a Reflected Cross-Site Scripting (XSS) vulnerability was identified in the /pet/profile_pet.php?id_pet= endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the id_pet parameter. This vulnera
nvd
CVE-2025-58452P4MEDIUMCVSS 6.1fixed in 3.4.112025-09-08
CVE-2025-58452 [MEDIUM] CWE-79 CVE-2025-58452: WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerabi WeGIA is a Web manager for charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the listar_despachos.php endpoint of the WeGIA application prior to version 3.4.11. This vulnerability allows attackers to inject malicious scripts in the id_memorando parameter. Version 3.4.11 contains a patch.
nvd
CVE-2025-23036P4MEDIUMCVSS 5.4fixed in 3.2.72025-01-14
CVE-2025-23036 [MEDIUM] CWE-79 CVE-2025-23036: WeGIA is an open source web manager with a focus on the Portuguese language and charitable instituti WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Reflected Cross-Site Scripting (XSS) vulnerability was identified in the `pre_cadastro_funcionario.php` endpoint of the WeGIA application. This vulnerability allows attackers to inject malicious scripts in the `msg_e` parameter. The application
nvd
Labredescefetrj Wegia vulnerabilities | cvebase