
🚨*CVE* CVE-2026-31894 WeGIA is a web manager for charitable institutions. In 3.6.5, The patched loadBackupDB() extracts tar.gz archives to a temporary directory using PHP's PharData class,… https://www.cve.org/CVERecord?id=CVE-2026-31894 ----- Traducción: CVE-2026-31894 WeG… http://infoflow.cloud`
Post summary
The text reports CVE-2026-31894, describing a flaw in WeGIA’s loadBackupDB() that improperly extracts tar.gz archives using PHP’s PharData class. No PoC, exploit, or active exploitation is mentioned, and patch details are not explicitly provided.

