Wegia · Wegia · CVE-2026-42870
**Name of the Vulnerable Software and Affected Versions**
WeGIA versions prior to 3.7.0
**Description**
A Stored Cross-Site Scripting (XSS) flaw exists, which allows a malicious script to be persistently stored on the server. This occurs at the 'funcionario/profile funcionario.php?id funcionario=2' endpoint when a payload is injected into the `Description` field and the profile is saved. The script executes automatically whenever the profile page is accessed.
**Recommendations**
Update to version 3.7.0.