CVE-2026-33136Disclosure(wegia / wegia)

LOWCVSS 6.1 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wegia wegia systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An attacker can inject arbitrary JavaScript or HTML tags into the sccd GET parameter, which is then directly echoed into the HTML response without any sanitization or encoding. The script /html/memorando/listar_memorandos_ativos.php handles dynamic success messages to users using query string parameters. Similar to other endpoints in the Memorando module, it checks if $_GET['msg'] equals 'success'. If this condition is met, it directly concatenates and reflects $_GET['sccd'] into an HTML alert <div>. This issue is resolved in version 3.6.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 8 signals
  • Disclosure: 7 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 5 mentions (2026-03-20); latest day: 1
  • 8 total mentions across 3 days

Affected systems

Vendors
Products
wegia

Deep dive

Activity timeline8 mentions / 3d
01345Mentions · 2026-03-20: 5Mentions · 2026-03-22: 2Mentions · 2026-03-24: 1Patch / Workaround · 2026-03-24: 1Technical Details · 2026-03-20: 5Technical Details · 2026-03-22: 2Technical Details · 2026-03-24: 103-2003-2203-24
Signal classification2 categories
Disclosure
787.5%
General
112.5%
Referenced assets9 URLs
Classification over time
DateTotalLabels
2026-03-205
Disclosure4General1
2026-03-222
Disclosure2
2026-03-241
Disclosure1
Full discourse8 posts
  • NCIIPC India@NCIIPC
    Disclosure

    Critical Reflected Cross-Site Scripting (#XSS) Vulnerability has been discovered in #WeGIA, a Web Manager for charitable institutions. Users are advised to follow OEM Security Advisories to remain safe! #CVE-2026-33136 https://nvd.nist.gov/vuln/detail/CVE-2026-33136

    Post summary

    A critical reflected XSS vulnerability, CVE‑2026‑33136, has been disclosed for the WeGIA web manager; users are advised to consult OEM security advisories and the NVD entry for protection measures.

    00000194
    8.4K followersView on X
  • IntegSec@integ_sec
    Disclosure

    CVE-2026-33136: WeGIA Reflected XSS Vulnerability - What It Means for Your Business and How to Respond https://hubs.li/Q047QQkx0

    Post summary

    The snippet announces CVE-2026-33136 as a reflected XSS vulnerability in WeGIA and hints at guidance for business impact and response, but offers no PoC, exploit code, or details on patches or active exploitation.

    0000018
    29 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33136 WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos… https://www.cve.org/CVERecord?id=CVE-2026-33136

    Post summary

    The post announces CVE-2026-33136, a reflected XSS flaw in WeGIA web manager, affecting versions 3.6.6 and earlier. No exploitation details or mitigations are provided.

    0000087
    56.8K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-33136 - Critical WeGIA is a web manager for charitable institutions. Versions 3.6.6 and below have a Reflected Cross-Site Scripting (XSS) vulnerability in the listar_memorandos_ativos.php endpoint. An att... https://www.thehackerwire.com/vulnerability/CVE-2026-33136/ https://t.co/tDh2nfobWL

    Post summary

    The post announces a critical reflected XSS flaw in WeGIA versions 3.6.6 and below, without providing PoC or exploit details.

    0000041
    138 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33136: WeGIA has Reflected Cross-Site S... Direct GET parameter reflection in charitable institution management software - perfect phishing vector for social engi... https://zerodaysignal.com/vulnerability/CVE-2026-33136 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    A new vulnerability, CVE‑2026‑33136, has been announced, describing a reflected cross‑site scripting issue that could be used for phishing. No exploitation evidence, PoC, or patch information is provided.

    0000046
    155 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33136 - WeGIA has Reflected Cross-Site Scripting (XSS) in `listar_memorandos_ativos.php` via `sccd` parameter Intel Report: https://ift.tt/BJiM32C

    Post summary

    The tweet announces a newly disclosed reflected XSS vulnerability (CVE-2026-33136) affecting WeGIA’s listar_memorandos_ativos.php via the sccd parameter, without providing PoC, exploit code, or patch details.

    0000029
    334 followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-33136: CRITICAL] WeGIA, a web manager for charities, had an XSS vulnerability in versions 3.6.6 and below. Attackers could inject JavaScript/HTML into listar_memorandos_ativos.php endpoint. Update ...#cve,CVE-2026-33136,#cybersecurity https://cvefind.com/CVE-2026-33136

    Post summary

    The post announces a critical XSS flaw in WeGIA versions 3.6.6 and earlier, describing the injection vector but providing no evidence of active exploitation, PoC, or patch details.

    0000046
    604 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-33136 Reflected XSS Vulnerability in WeGIA Web Manager Versions 3.6.6 a... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-33136 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The tweet announces CVE‑2026‑33136 as a reflected XSS flaw in WeGIA Web Manager 3.6.6, linking to a detail page but providing no PoC, exploit, patch, or evidence of active exploitation.

    0000034
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia---

Explore more