🔐 CVE Alert

CVE-2026-40286

HIGH 7.5

WeGIA has Cross-Site Scripting in Controle de Contribuição

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) function. By injecting a payload into the 'Member Name' (Nome Sócio) field, the script is persistently stored in the database. Consequently, the payload is executed whenever a user navigates to certain URL. Version 3.6.10 fixes the issue.

CWE CWE-79
Vendor labredescefetrj
Product wegia
Published Apr 17, 2026
Stay Ahead of the Next One

Get instant alerts for labredescefetrj wegia

Be the first to know when new high vulnerabilities affecting labredescefetrj wegia are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None

Affected Versions

LabRedesCefetRJ / WeGIA
< 3.6.10

References

NVD ↗ CVE.org ↗ EPSS Data ↗
github.com: https://github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-42rc-rvrx-cmmw