wegia

179 tracked vulnerabilities.

CVE-2026-23726 MEDIUM
WeGIA < 3.6.2 - Open Redirect via nextPage Parameter
Jan 16, 2026
CVSS 6.1
EPSS 0.00
CVE-2026-23725 MEDIUM
WeGIA < 3.6.2 - Stored Cross-Site Scripting in Adopters Information Table
Jan 16, 2026
CVSS 5.4
EPSS 0.00
CVE-2026-23724 MEDIUM
WeGIA < 3.6.2 - Stored Cross-Site Scripting in Atendido Selection Dropdown
Jan 16, 2026
CVSS 4.3
EPSS 0.00
CVE-2026-23723 HIGH
WeGIA < 3.6.2 - Authenticated SQL Injection via Atendido_ocorrenciaControle id_memorando Parameter
Jan 16, 2026
CVSS 7.2
EPSS 0.00
CVE-2026-23722 CRITICAL
WeGIA < 3.6.2 - Unauthenticated Reflected Cross-Site Scripting via id_memorando Parameter
Jan 16, 2026
CVSS 9.1
EPSS 0.00
CVE-2025-67501 HIGH
WeGIA < 3.5.5 - SQL Injection via id_categoria Parameter
Dec 10, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-67496 MEDIUM
WeGIA < 3.5.5 - Stored Cross-Site Scripting in Employee Selection Dropdown
Dec 09, 2025
CVSS 4.3
EPSS 0.00
CVE-2025-62598 MEDIUM
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via editar_info_pessoal.php Action Parameter
Oct 21, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62597 MEDIUM
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via editar_info_pessoal.php sql Parameter
Oct 21, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62361 MEDIUM
WeGIA < 3.5.0 - Open Redirect via control.php nextPage Parameter
Oct 13, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62360 HIGH
WeGIA < 3.5.1 - SQL Injection via id_dependente Parameter
Oct 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-62359 MEDIUM
WeGIA >=3.4.11 <3.5.0 - Reflected Cross-Site Scripting via id_pet Parameter
Oct 13, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-62358 MEDIUM
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via Log Parameter
Oct 13, 2025
CVSS 5.4
EPSS 0.00
CVE-2025-62179 HIGH
WeGIA < 3.5.1 - SQL Injection via CPF Parameter in Funcionario Endpoint
Oct 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-62178 LOW
WeGIA < 3.5.1 - Reflected Cross-Site Scripting via idatendido Parameter
Oct 13, 2025
CVSS 3.5
EPSS 0.00
CVE-2025-62177 HIGH
WeGIA < 3.5.1 - SQL Injection via id_funcionario Parameter
Oct 13, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-61665 HIGH
WeGIA < 3.5.0 - Unauthenticated Sensitive Information Exposure via get_relatorios_socios.php Endpoint
Oct 02, 2025
CVSS 7.5
EPSS 0.00
CVE-2025-61606 MEDIUM
WeGIA < 3.5.0 - Open Redirect via control.php nextPage Parameter
Oct 02, 2025
CVSS 6.1
EPSS 0.00
CVE-2025-61605 CRITICAL
WeGIA < 3.5.0 - SQL Injection via id_pet Parameter
Oct 02, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-61604 HIGH
WeGIA < 3.5.0 - Cross-Site Request Forgery via Almoxarifado Delete Operation
Oct 02, 2025
CVSS 7.1
EPSS 0.00
CVE-2025-61603 CRITICAL
WeGIA < 3.5.0 - SQL Injection via descricao Parameter
Oct 02, 2025
CVSS 9.8
EPSS 0.00
CVE-2025-59939 HIGH
WeGIA < 3.5.0 - SQL Injection via control.php id_produto Parameter
Sep 27, 2025
CVSS 8.8
EPSS 0.00
CVE-2025-58745 CRITICAL
WeGIA < 3.4.11 - Unauthenticated Arbitrary File Upload via Excel MIME Type Bypass
Sep 08, 2025
CVSS 9.9
EPSS 0.01
CVE-2025-58454 HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_memorando Parameter
Sep 08, 2025
CVSS 8.2
EPSS 0.00
CVE-2025-58453 HIGH
WeGIA < 3.4.11 - Authenticated SQL Injection via id_anexo Parameter
Sep 08, 2025
CVSS 8.2
EPSS 0.00
Products
wegia 179