CVE-2026-33133Disclosure(wegia / wegia)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without any content validation. An attacker can craft a backup archive containing arbitrary SQL statements that create rogue administrator accounts, modify existing passwords, or execute any database operation. This was introduced in commit 370104c. This issue was patched in version 3.6.7.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-03-20); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
wegia

2 versions affected across 1 product

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-03-20: 3Mentions · 2026-03-22: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-22: 103-2003-22
Signal classification2 categories
Disclosure
375.0%
General
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-203
Disclosure2General1
2026-03-221
Disclosure1
Full discourse4 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33133 WeGIA is a web manager for charitable institutions. In versions 3.6.5 and 3.6.6, the loadBackupDB() function imports SQL files from uploaded backup archives without a… https://www.cve.org/CVERecord?id=CVE-2026-33133

    Post summary

    The snippet highlights a flaw in WeGIA's loadBackupDB() function that imports SQL files from backup archives, indicating a potential vulnerability without evidence of exploitation, PoC, or patch.

    0000095
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-33133 - LabRedesCefetRJ - WeGIA - https://www.redpacketsecurity.com/cve-alert-cve-2026-33133-labredescefetrj-wegia/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-33133 #labredescefetrj #wegia

    Post summary

    The message announces a CVE alert for CVE-2026-33133 related to LabRedesCefetRJ and WeGIA, but it offers no further technical details, exploits, or patch information.

    0000076
    3.6K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33133 - WeGIA has an arbitrary SQL execution vulnerability via crafted backup archive Intel Report: https://ift.tt/ReDB8ZU

    Post summary

    A threat alert announces the discovery of CVE‑2026‑33133, identifying an arbitrary SQL execution vulnerability in WeGIA via crafted backup archives. No immediate exploitation, PoC, or patch information is provided.

    0000026
    334 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33133 SQL Injection in WeGIA Web Manager via Unvalidated Backup Archive Import https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33133

    Post summary

    The post identifies a CVE (CVE-2026-33133) as a SQL injection issue in WeGIA Web Manager but lacks any details on proof of concept, exploitation tools, active usage, or mitigation steps.

    0000033
    4.0K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia3.6.5--
Appwegiawegia3.6.6--

Explore more