Stored Cross-Site Scripting in WeGIA Web Manager for Charities
CVE-2026-45026
6.8MEDIUM
What is CVE-2026-45026?
The WeGIA web manager for charitable institutions prior to version 3.7.3 contains a Stored Cross-Site Scripting (XSS) vulnerability. This flaw can be exploited by an authenticated user to inject malicious JavaScript into the Processo de Aceitação page. When other users access this compromised page, the injected script executes, potentially leading to session hijacking or account takeover. The issue has been addressed in version 3.7.3, which provides a necessary fix for this security risk.
Affected Version(s)
WeGIA < 3.7.3
