These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
WeGIA, a web management platform for charitable institutions, contains an open redirect vulnerability in versions prior to 3.7.3. The flaw exists in the /WeGIA/controle/control.php endpoint, where the nextPage parameter lacks validation when used with metodo=listarTodos and nomeClasse=InternoControle. Attackers can craft URLs that redirect users to arbitrary external domains while appearing to originate f [truncated]
WeGIA versions prior to 3.7.3 use unsalted SHA-256 for password hashing in authentication and password-change flows. SHA-256 is a fast, general-purpose hash unsuitable for password storage; without a salt, identical passwords yield identical digests, enabling efficient rainbow-table attacks against the credential database. The vulnerability is fixed in version 3.7.3.
CVE-2026-35475 is a medium-severity vulnerability in WeGIA, a web manager for charitable institutions. The vulnerability exists due to an unvalidated redirect parameter in versions prior to 3.6.9. This parameter is taken directly from the URL query string without proper validation or whitelist checks, allowing attackers to manipulate the redirect location. The vulnerability has a CVSS score of 5.1 and a m [truncated]
CVE-2026-35474 is an open redirect vulnerability in the WeGIA web application prior to version 3.6.9. The vulnerability arises from the lack of URL validation or whitelist checks for the redirect parameter, which is taken directly from the GET request and used in a header Location call. This could potentially allow attackers to redirect users to malicious sites. Users of WeGIA version prior to 3.6.9 shoul [truncated]
CVE-2026-35473 is an Open Redirect vulnerability in WeGIA, a Web manager for charitable institutions. The vulnerability exists in the /WeGIA/controle/control.php endpoint, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IentradaControle. This allows attackers to redirect users to arbitrary external websites, which can be abused for phishing attacks, credential [truncated]
CVE-2026-35472 is an Open Redirect vulnerability in WeGIA, a Web manager for charitable institutions. The vulnerability was patched in version 3.6.9. This vulnerability allows attackers to redirect users to arbitrary external websites, which can be abused for phishing attacks, credential theft, malware distribution, and social engineering using the trusted WeGIA domain. The vulnerability has a CVSS score [truncated]
CVE-2026-35399 is a stored XSS vulnerability in WeGIA, a Web manager for charitable institutions, prior to version 3.6.9. An attacker can inject malicious scripts through a backup filename, potentially leading to unauthorized execution of malicious code in the victim's browser. This vulnerability could compromise session data or execute actions on behalf of the user. The vulnerability is fixed in version [truncated]
CVE-2026-35398 is an Open Redirect vulnerability in WeGIA, a Web manager for charitable institutions, prior to version 3.6.9. The vulnerability exists in the /WeGIA/controle/control.php endpoint, specifically through the nextPage parameter when combined with metodo=listarTodos & listarId_Nome and nomeClasse=OrigemControle. The application fails to validate or restrict the nextPage parameter, allowing atta [truncated]
CVE-2026-35396 is an Open Redirect vulnerability in WeGIA, a Web manager for charitable institutions. The vulnerability exists in the /WeGIA/controle/control.php endpoint, specifically through the nextPage parameter when combined with metodo=listarId and nomeClasse=IsaidaControle. This allows attackers to redirect users to arbitrary external websites, which can be abused for phishing attacks, credential t [truncated]
CVE-2026-35395 is a SQL injection vulnerability in WeGIA, a web manager for charitable institutions. The vulnerability exists in the DespachoDAO.php file, where the id_memorando parameter is extracted from $_REQUEST without validation and directly interpolated into SQL queries. This allows any authenticated user to execute arbitrary SQL commands against the database, potentially leading to data breaches o [truncated]