CVE-2026-23722 - WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrar...

CVE-2026-23722 - WeGIA has a Reflected Cross-Site Scripting (XSS) vulnerability allowing arbitrar...

CVE ID : CVE-2026-23722 Published : Jan. 16, 2026, 7:29 p.m. | 47 minutes ago Description : WeGIA is a Web Manager for Charitable Institutions. Prior to 3.6.2, a Reflected Cross-Site Scripting (XSS) vulnerability was discovered in the WeGIA system, specifically within the html/memorando/insere_despacho.php file. The application fails to properly sanitize or encode user-supplied input via the id_memorando GET parameter before reflecting it into the HTML source (likely inside a

CVE Details

Published
Jan. 16, 2026
Affected Product: php
Impact: XSS