Stored Cross-Site Scripting in WeGIA Web Manager for Charities
CVE-2026-45026

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 May 2026

What is CVE-2026-45026?

The WeGIA web manager for charitable institutions prior to version 3.7.3 contains a Stored Cross-Site Scripting (XSS) vulnerability. This flaw can be exploited by an authenticated user to inject malicious JavaScript into the Processo de Aceitação page. When other users access this compromised page, the injected script executes, potentially leading to session hijacking or account takeover. The issue has been addressed in version 3.7.3, which provides a necessary fix for this security risk.

Affected Version(s)

WeGIA < 3.7.3

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.