CVE-2025-61603Critical· 9.8▾ MidnightWeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability …
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.4%
WeGIA is a Web manager for charitable institutions. Versions 3.4.12 and below include an SQL Injection vulnerability which was identified in the /controle/control.php endpoint, specifically in the descricao parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This issue is fixed in version 3.5.0.
wegia < 3.5.0Upgrade past the affected range:
wegia 3.5.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-61605Critical· 9.8WeGIA is an open source web manager with a focus on charitable institutions
CVE-2025-62360High· 8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the i…
CVE-2025-62177High· 8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users
CVE-2025-62179High· 8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users
CVE-2025-61665High· 7.5WeGIA is an open source web manager with a focus on charitable institutions
CVE-2025-61606Medium· 6.1WeGIA is an open source web manager with a focus on charitable institutions