Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.8

WeGIA Web Manager: SQL Injection in Product Restore Feature

CVE-2026-31895
Summary

WeGIA's web manager for charitable institutions has a security flaw in its product restore feature that could allow an attacker to access sensitive data. This flaw is fixed in version 3.6.6, which you should update to if you haven't already. To protect your data, it's essential to keep your software up to date.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versionsFix available
wegia wegia <= 3.6.6
Original title
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_p...
Original description
WeGIA is a web manager for charitable institutions. Prior to version 3.6.6, WeGIA (Web gerenciador para instituições assistenciais) contains a SQL injection vulnerability in html/matPat/restaurar_produto.php. The id_produto parameter from $_GET is directly interpolated into SQL queries without parameterization or sanitization. This vulnerability is fixed in 3.6.6.
nvd CVSS3.1 8.8
Vulnerability type
CWE-89 SQL Injection
Published: 11 Mar 2026 · Updated: 13 Mar 2026 · First seen: 11 Mar 2026