ZeroHour

CVE-2026-40284

CVSS 3.1
6.8 medium
EPSS
<1%p14
Published
()
Modified
Description

WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript via the "Destinatário" field. The payload is stored and later executed when viewing the dispatch page, impacting other users. Version 3.6.10 fixes the issue.

Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.