Wegia
173 CVEs tracked since 2024. Since Dec 2024, none of them reached CISA KEV.
Wegia CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2024-12 | 4 | 0 |
| 2025-01 | 37 | 0 |
| 2025-02 | 22 | 0 |
| 2025-03 | 13 | 0 |
| 2025-04 | null or fewer | |
| 2025-05 | null or fewer | |
| 2025-06 | 9 | 0 |
| 2025-07 | 31 | 0 |
| 2025-08 | 11 | 0 |
| 2025-09 | 5 | 0 |
| 2025-10 | 14 | 0 |
| 2025-11 | null or fewer | |
| 2025-12 | null or fewer | |
| 2026-01 | 10 | 0 |
| 2026-02 | null or fewer | |
| 2026-03 | 8 | 0 |
| 2026-04 | 9 | 0 |
Products
The products that kept showing up in Wegia's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Wegia.
- CVE-2026-40283WeGIA has stored XSS in profile_paciente.php6.8
- CVE-2026-35475WeGIA - Open Redirect - backup redirection — Unvalidated $_GET['redirect']6.1
- CVE-2026-35474WeGIA - Open Redirect - atualizacao redirection - Unvalidated $_GET['redirect']6.1
- CVE-2026-35473WeGIA - Open Redirect - IentradaControle - listarId() - Unvalidated $_GET['nextPage']6.1
- CVE-2026-35399WeGIA has Stored XSS in backup file names6.1
- CVE-2026-35472WeGIA - Open Redirect - EstoqueControle - listarTodos() - Unvalidated $_GET['nextPage']6.1
- CVE-2026-35398WeGIA - Open Redirect - OrigemControle - listarTodos() & listarId_Nome() - Unvalidated $_GET['nextPage']6.1
- CVE-2026-35396WeGIA - Open Redirect - IsaidaControle - listarId() - Unvalidated $_GET['nextPage']6.1
- CVE-2026-35395WeGIA has a SQL Injection in DespachoDAO.php via id_memorando parameter8.8
- CVE-2026-33991WeGIA has SQL Injection in deletar_tag.php8.8
- CVE-2026-33136WeGIA has Reflected Cross-Site Scripting (XSS) in `listar_memorandos_ativos.php` via `sccd` parameter9.3
- CVE-2026-33135WeGIA has Reflected Cross-Site Scripting (XSS) in `novo_memorandoo.php` via `sccs` parameter9.3
- CVE-2026-33134WeGIA has Authenticated Time-Based Blind SQL Injection in `restaurar_produto.php` via `id_produto` parameter9.3
- CVE-2026-33133WeGIA has an arbitrary SQL execution vulnerability via crafted backup archive7.2
- CVE-2026-31896WeGIA has a Time-Based Blind SQL Injection in remover_produto_ocultar.php9.8
The record
- Peak rank
- #25 in Jan 2025
- Busiest month shown
- Jan 2025, 37 CVEs
- Months with a KEV entry
- 0 since Dec 2024
- Monthly snapshots
- 12 since 2024