CVE-2026-31896Disclosure(wegia / wegia)

LOWCVSS 9.8 · CRITICAL

Signal is active with 4 mentions in latest observed window

Immediate actions

  • Patch wegia wegia systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produto_ocultar.php script uses extract($_REQUEST) to populate local variables and then directly concatenates these variables into a SQL query executed via PDO::query. This allows an authenticated (or auth-bypassed) attacker to execute arbitrary SQL commands. This can be used to exfiltrate sensitive data from the database or, as demonstrated in this PoC, cause a time-based delay (denial of service). This vulnerability is fixed in 3.6.6.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • 4 total mentions across 1 day

Affected systems

Vendors
Products
wegia

Deep dive

Activity timeline4 mentions / 1d
01234Mentions · 2026-03-11: 4Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-11: 403-11
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Full discourse4 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-31896 WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produt… https://www.cve.org/CVERecord?id=CVE-2026-31896 ----- Traducción: CVE-2026-31896 WeG… http://infoflow.cloud`

    Post summary

    The post announces a critical SQL injection flaw in WeGIA web manager prior to version 3.6.6, providing basic technical details but no proof‑of‑concept, exploit, or patch information.

    0000029
    57 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-31896 WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, a critical SQL injection vulnerability exists in the WeGIA application. The remover_produt… https://www.cve.org/CVERecord?id=CVE-2026-31896

    Post summary

    The statement announces a critical SQL injection flaw in WeGIA versions below 3.6.6, providing no PoC, exploit code, active use, patch information, or debunking details.

    00000207
    56.6K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-31896: CRITICAL] Critical SQL injection vulnerability in WeGIA web manager prior to version 3.6.6 enables attackers to execute arbitrary SQL commands or exfiltrate sensitive data. The issue is reso...#cve,CVE-2026-31896,#cybersecurity https://cvefind.com/CVE-2026-31896

    Post summary

    The tweet announces a critical SQL injection vulnerability in WeGIA web manager before version 3.6.6, indicating that updating to 3.6.6 mitigates the issue, with no PoC, exploit, or active exploitation claims reported.

    0000041
    600 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-31896: WeGIA has a Time-Based Blind SQL... extract($_REQUEST) + direct SQL concatenation = instant pwn for any attacker who can reach the endpoint, no auth requir... https://zerodaysignal.com/vulnerability/CVE-2026-31896 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet reports a time-based blind SQL injection in WeGIA (CVE-2026-31896) that allows unauthenticated attackers to gain control, but no PoC, exploit code, patch, or evidence of active exploitation is given.

    0000056
    143 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia---

Explore more