CVE-2026-33134Disclosure(wegia / wegia)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch wegia wegia systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vulnerability allows an authenticated attacker to inject arbitrary SQL commands via the id_produto GET parameter, leading to full database compromise. In the script /html/matPat/restaurar_produto.php, the application retrieves the id_produto parameter directly from the $_GET global array and interpolates it directly into two SQL query strings without any sanitization, type-casting (e.g., (int)), or using parameterized (prepare/execute) statements. This issue has been fixed in version 3.6.6.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 6 classified signals
  • Peaked 2d ago at 5 mentions (2026-03-20); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
wegia

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-03-20: 5Mentions · 2026-03-21: 1Mentions · 2026-03-22: 1PoC Mentioned / Linked · 2026-03-20: 1Patch / Workaround · 2026-03-20: 1Technical Details · 2026-03-20: 5Technical Details · 2026-03-22: 103-2003-2103-22
Signal classification2 categories
Disclosure
685.7%
Patch
114.3%
Referenced assets7 URLs
Classification over time
DateTotalLabels
2026-03-205
Disclosure4Patch1
2026-03-211
Disclosure1
2026-03-221
Disclosure1
Full discourse7 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33134 WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto… https://www.cve.org/CVERecord?id=CVE-2026-33134

    Post summary

    The statement reports a newly disclosed authenticated SQL Injection vulnerability in WeGIA versions 3.6.5 and earlier.

    0000084
    56.8K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-33134 - LabRedesCefetRJ - WeGIA - https://www.redpacketsecurity.com/cve-alert-cve-2026-33134-labredescefetrj-wegia/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-33134 #labredescefetrj #wegia

    Post summary

    The tweet merely announces CVE‑2026‑33134, directing readers to an external link without providing technical details, PoC references, or mitigation information.

    0000054
    3.6K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33134 - Critical WeGIA is a web manager for charitable institutions. Versions 3.6.5 and below contain an authenticated SQL Injection vulnerability in the html/matPat/restaurar_produto.php endpoint. The vu... https://www.thehackerwire.com/vulnerability/CVE-2026-33134/ https://t.co/Hrq2G8Cme0

    Post summary

    The tweet announces that versions 3.6.5 and below of WeGIA contain an authenticated SQL injection vulnerability in the restaurar_produto.php endpoint, but does not provide a PoC, exploit code, or patch information.

    0000040
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33134: WeGIA ... Raw GET parameter interpolation into dual SQL queries = instant database ownership for any authenticated user. #SQLInjection #WeGIA #CriticalRCE. https://zerodaysignal.com/vulnerability/CVE-2026-33134 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-33134 for WeGIA, noting raw GET parameter interpolation that causes SQL injection giving database ownership to authenticated users, with a link for further details.

    0000067
    155 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33134 - WeGIA has Authenticated Time-Based Blind SQL Injection in `restaurar_produto.php` via `id_produto` parameter Intel Report: https://ift.tt/Gd7Whfr

    Post summary

    The alert highlights a new authenticated time‑based blind SQL injection vulnerability in WeGIA’s restaurar_produto.php, but it does not provide a PoC, exploit code, or patch information.

    0000027
    334 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-33134 Authenticated SQL Injection in WeGIA Web Manager Versions 3.6.5 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33134

    Post summary

    A brief disclosure of CVE-2026-33134, describing an authenticated SQL injection vulnerability in WeGIA Web Manager versions 3.6.5 and older, with a link to more details but no PoC, exploit, or patch information.

    0000028
    4.0K followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33134: CRITICAL] WeGIA web manager for charities had a SQL Injection flaw in versions 3.6.5 and under, which allowed attackers to manipulate the database. Ensure version 3.6.6 or higher is in use.#cve,CVE-2026-33134,#cybersecurity https://cvefind.com/CVE-2026-33134

    Post summary

    The post announces a critical SQL injection vulnerability in WeGIA web manager versions 3.6.5 and under, and recommends upgrading to 3.6.6 or newer to mitigate the issue.

    0000038
    604 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia---

Explore more