Vulnerabilities
Report: CVE-2026-33991 - WeGIA has SQL Injection in deletar_tag.php
CVE ID :CVE-2026-33991 Published : March 27, 2026, 11:17 p.m. | 37 minutes ago Description :WeGIA is a web manager for charitable institutions. Prior to version 3.6.7, the file `html/socio/sistema/deletar_tag.php` uses `extract($_REQUEST)` on line 14 and directly concatenates the `$id_tag` variable into SQL queries on lines 16-17 without prepared statements or sanitization. Version 3.6.7 patches the vulnerability. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...