PT-2026-33514 · Wegia · Wegia

Published

2026-04-17

·

Updated

2026-04-18

·

CVE-2026-40286

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions WeGIA versions prior to 3.6.10
Description A Stored Cross-Site Scripting (XSS) issue exists in the 'Member Registration' (Cadastrar Sócio) function. By injecting a payload into the Member Name (Nome Sócio) field, the script is persistently stored in the database and executed when a user navigates to certain URLs.
Recommendations Update to version 3.6.10.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-40286

Affected Products

Wegia