
CVE-2026-33991 WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and dir… https://www.cve.org/CVERecord?id=CVE-2026-33991
Post summary
CVE‑2026‑33991 surfaces an insecure use of PHP’s `extract($_REQUEST)` in WeGIA before v3.6.7, which is presumably fixed in that version.


