wegia
179 tracked vulnerabilities.
CVE-2026-23726
MEDIUM
WeGIA < 3.6.2 - Open Redirect via nextPage Parameter
Jan 16, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-23725
MEDIUM
WeGIA < 3.6.2 - Stored Cross-Site Scripting in Adopters Information Table
Jan 16, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-23724
MEDIUM
WeGIA < 3.6.2 - Stored Cross-Site Scripting in Atendido Selection Dropdown
Jan 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-23723
HIGH
WeGIA < 3.6.2 - Authenticated SQL Injection via Atendido_ocorrenciaControle id_memorando Parameter
Jan 16, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-23722
CRITICAL
WeGIA < 3.6.2 - Unauthenticated Reflected Cross-Site Scripting via id_memorando Parameter
Jan 16, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-67501
HIGH
WeGIA < 3.5.5 - SQL Injection via id_categoria Parameter
Dec 10, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-67496
MEDIUM
WeGIA < 3.5.5 - Stored Cross-Site Scripting in Employee Selection Dropdown
Dec 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62598
MEDIUM
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via editar_info_pessoal.php Action Parameter
Oct 21, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62597
MEDIUM
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via editar_info_pessoal.php sql Parameter
Oct 21, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62361
MEDIUM
WeGIA < 3.5.0 - Open Redirect via control.php nextPage Parameter
Oct 13, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62360
HIGH
WeGIA < 3.5.1 - SQL Injection via id_dependente Parameter
Oct 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-62359
MEDIUM
WeGIA >=3.4.11 <3.5.0 - Reflected Cross-Site Scripting via id_pet Parameter
Oct 13, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62358
MEDIUM
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via Log Parameter
Oct 13, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62179
HIGH
WeGIA < 3.5.1 - SQL Injection via CPF Parameter in Funcionario Endpoint
Oct 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-62178
LOW
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via idatendido Parameter
Oct 13, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-62177
HIGH
WeGIA < 3.5.1 - SQL Injection via id_funcionario Parameter
Oct 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-61665
HIGH
WeGIA < 3.5.0 - Unauthenticated Sensitive Information Exposure via get_relatorios_socios.php Endpoint
Oct 02, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-61606
MEDIUM
WeGIA < 3.5.0 - Open Redirect via control.php nextPage Parameter
Oct 02, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-61605
CRITICAL
WeGIA < 3.5.0 - SQL Injection via id_pet Parameter
Oct 02, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-61604
HIGH
WeGIA < 3.5.0 - Cross-Site Request Forgery via Almoxarifado Delete Operation
Oct 02, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-61603
CRITICAL
WeGIA < 3.5.0 - SQL Injection via descricao Parameter
Oct 02, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-59939
HIGH
WeGIA < 3.5.0 - SQL Injection via control.php id_produto Parameter
Sep 27, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-58745
CRITICAL
WeGIA < 3.4.11 - Unauthenticated Arbitrary File Upload via Excel MIME Type Bypass
Sep 08, 2025
CVSS 9.9
EPSS 0.01
CVE-2025-58454
HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_memorando Parameter
Sep 08, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-58453
HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_anexo Parameter
Sep 08, 2025
CVSS 8.2
EPSS 0.00
Products
Quick Filters