Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

WeGIA — Vulnerabilities & Security Advisories 181

All 181 CVE vulnerabilities found in WeGIA, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumeration (CWE) and Common Vulnerabilities and Exposures (CVE) data specifically for the WeGIA product managed by its respective vendor. It serves as a comprehensive repository for security researchers and system administrators seeking to understand the threat landscape associated with this specific software environment. The content collected here spans from the initial release of the product through the most recent security advisories, ensuring a chronological view of all documented flaws. Visitors can utilize this resource to track the vendor’s public security advisories over time, gaining insight into how quickly and effectively the developer addresses emerging threats. Furthermore, users can delve into specific weakness classes to understand the underlying technical nature of the bugs, such as buffer overflows or logic errors, rather than just their symptoms. The page also allows for a deep dive into the product’s vulnerability history, enabling analysts to correlate security incidents with specific software versions or updates. By centralizing this information, the page facilitates better risk assessment and informed decision-making for maintenance teams. It provides a structured overview that helps distinguish between minor configuration issues and critical exploits affecting system integrity. This aggregation aims to provide transparency and clarity regarding the security posture of WeGIA without overwhelming the reader with raw, unorganized data points.

Vendor: nilsonLazarin

CVE IDTitleCVSSSeverityPublished
CVE-2026-45335 WeGIA: Middleware whitelist bypass → open redirect via InternoControle.nextPage CWE-601 5.4 Medium2026-05-27
CVE-2026-45027 WeGIA: Use of Weak Password Hashing Algorithm (SHA-256, no salt) in html/login.php CWE-759 5.9 Medium2026-05-27
CVE-2026-45026 WeGIA: Stored XSS in html/atendido/processo_aceitacao.php CWE-79 6.8 Medium2026-05-11
CVE-2026-45025 WeGIA: Stored XSS in html/atendido/etapa_processo.php CWE-79 6.8 Medium2026-05-11
CVE-2026-42873 WeGIA: Error Handling Upload DocDependente CWE-200--2026-05-11
CVE-2026-42872 WeGIA: Reflected XSS in listar_arquivos_etapa.php CWE-79 6.1 Medium2026-05-11
CVE-2026-42870 WeGIA: Cross-Site Scripting (XSS) Stored endpoint 'informacao_adicional.php' parameter 'descricao' CWE-79--2026-05-11
CVE-2026-42871 WeGIA: Error Handling familiar_docfamiliar CWE-200--2026-05-11
CVE-2026-40286 WeGIA has Cross-Site Scripting in Controle de Contribuição CWE-79 7.5 High2026-04-17
CVE-2026-40285 WeGIA has SQL Injection via Session Variable Override in DespachoControle.php CWE-89 8.8 High2026-04-17
CVE-2026-40284 WeGIA has stored XSS in listar_despachos.php CWE-79 6.8 Medium2026-04-17
CVE-2026-40282 WeGIA has stored XSS in intercorrencia_visualizar.php CWE-79 5.4AIMediumAI2026-04-17
CVE-2026-40283 WeGIA has stored XSS in profile_paciente.php CWE-79 6.8 Medium2026-04-17
CVE-2026-35475 WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect'] CWE-601 6.1AIMediumAI2026-04-06
CVE-2026-35474 WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect'] CWE-601 6.1AIMediumAI2026-04-06
CVE-2026-35473 WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage'] CWE-601 6.1AIMediumAI2026-04-06
CVE-2026-35399 WeGIA has Stored XSS in backup file names CWE-79 5.4AIMediumAI2026-04-06
CVE-2026-35472 WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage'] CWE-601 6.1AIMediumAI2026-04-06
CVE-2026-35398 WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage'] CWE-601 6.1AIMediumAI2026-04-06
CVE-2026-35396 WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage'] CWE-601 6.1AIMediumAI2026-04-06
CVE-2026-35395 WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter CWE-89 8.8 High2026-04-06
CVE-2026-33991 WeGIA has SQL Injection in deletar_tag.php CWE-89 8.8 High2026-03-27
CVE-2026-33136 WeGIA has Reflected Cross-Site Scripting (XSS) in `listar_memorandos_ativos.php` via `sccd` parameter CWE-79 9.3 Critical2026-03-20
CVE-2026-33135 WeGIA has Reflected Cross-Site Scripting (XSS) in `novo_memorandoo.php` via `sccs` parameter CWE-79 9.3 Critical2026-03-20
CVE-2026-33134 WeGIA has Authenticated Time-Based Blind SQL Injection in `restaurar_produto.php` via `id_produto` parameter CWE-89 9.3 Critical2026-03-20
CVE-2026-33133 WeGIA has an arbitrary SQL execution vulnerability via crafted backup archive CWE-89 8.8 -2026-03-20
CVE-2026-31896 WeGIA has a Time-Based Blind SQL Injection in remover_produto_ocultar.php CWE-89 9.8 Critical2026-03-11
CVE-2026-31895 WeGIA has a SQL Injection via Direct Query Interpolation in restaurar_produto.php CWE-89 8.8 High2026-03-11
CVE-2026-31894 WeGIA affected by arbitrary file read via symlink in backup restore CWE-59 7.5AIHighAI2026-03-11
CVE-2026-28411 WeGIA Vulnerable to Authentication Bypass via `extract($_REQUEST)` CWE-288 9.8 Critical2026-02-27

All 181 known CVE vulnerabilities affecting WeGIA with full Chinese analysis, references, and POCs where available.