CVE-2025-62360High· 8.8▾ MidnightPoC availableWeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the i…
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 48.4 · likelihood 0.2 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.9%
Exploit-DB (last check)
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users.Prior to 3.5.1, a SQL Injection vulnerability was identified in the /html/funcionario/dependente_documento.php endpoint, specifically in the id_dependente parameter. This vulnerability allows attackers to execute arbitrary SQL commands, compromising the confidentiality, integrity, and availability of the database. This vulnerability is fixed in 3.5.1.
wegia < 3.5.1Upgrade past the affected range:
wegia 3.5.1Connected by shared product, vendor, weakness, or advisory.
CVE-2025-62177High· 8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users
CVE-2025-62179High· 8.8WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users
CVE-2026-54767Critical· 9.1WeGIA is a web manager for charitable institutions
CVE-2026-54670Critical· 9.1WeGIA is a web manager for charitable institutions
CVE-2026-54671High· 8.8WeGIA is a web manager for charitable institutions
CVE-2026-76634Medium· 6.5WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request ext…