CVE-2026-33991Patch(wegia / wegia)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch wegia wegia systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` variable into SQL queries on lines 16-17 without prepared statements or sanitization. Version 3.6.7 patches the vulnerability.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • wegia

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-27); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
wegia

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-27: 2Mentions · 2026-03-28: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-28: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-28: 103-2703-28
Signal classification2 categories
Patch
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-03-272
Disclosure1Patch1
2026-03-281
Patch1
Full discourse3 posts
  • CVE@CVEnew
    Patch

    CVE-2026-33991 WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and dir… https://www.cve.org/CVERecord?id=CVE-2026-33991

    Post summary

    CVE‑2026‑33991 surfaces an insecure use of PHP’s `extract($_REQUEST)` in WeGIA before v3.6.7, which is presumably fixed in that version.

    0000075
    56.9K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-33991 - High WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$... https://www.thehackerwire.com/vulnerability/CVE-2026-33991/ https://t.co/sU1T6YhChx

    Post summary

    The tweet announces CVE‑2026‑33991, highlighting a security flaw involving unsanitized user input via `extract($_REQUEST)` and direct string concatenation, but does not provide PoC, exploit code, or patch details.

    0000038
    163 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-33991: HIGH] Update to WeGIA version 3.6.7 for improved cyber security. Prior versions risk SQL injection due to unsanitized user input in `deletar_tag.php`.#cve,CVE-2026-33991,#cybersecurity https://cvefind.com/CVE-2026-33991

    Post summary

    The post reveals a SQL injection flaw in WeGIA's `deletar_tag.php` and advises users to upgrade to version 3.6.7 for remediation.

    0000043
    617 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appwegiawegia---

Explore more