CVE-2026-40282: WeGIA has stored XSS in intercorrencia_visualizar.php
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the Intercorrências notification page, which is executed when user access the the page, enabling session hijacking and account takeover. Version 3.6.10 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-40282?
CVE-2026-40282 is categorized as a medium-severity vulnerability due to its potential impact on user security.
How do I fix CVE-2026-40282?
To fix CVE-2026-40282, upgrade WeGIA to version 3.6.10 or later.
What types of attacks can CVE-2026-40282 enable?
CVE-2026-40282 can enable stored cross-site scripting (XSS) attacks, which may compromise user data and session integrity.
Who is affected by CVE-2026-40282?
CVE-2026-40282 affects authenticated users of WeGIA versions prior to 3.6.10.
Is there a known workaround for CVE-2026-40282?
There are no specific workarounds for CVE-2026-40282; upgrading the software is the recommended solution.