Unrated severityOSV Advisory· Published Jan 16, 2026· Updated Jan 16, 2026
WeGIA Stored Cross-Site Scripting (XSS) – atendido_idatendido Parameter on Occurrence Registration Page
CVE-2026-23724
Description
WeGIA is a web manager for charitable institutions. Prior to 3.6.2, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the html/atendido/cadastro_ocorrencia.php endpoint of the WeGIA application. The application does not sanitize user-controlled data before rendering it inside the “Atendido” selection dropdown. This vulnerability is fixed in 3.6.2.
Affected products
1- Range: 0.9.4-beta, 3.3.0, 3.3.1, …
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/LabRedesCefetRJ/WeGIA/pull/1333mitrex_refsource_MISC
- github.com/LabRedesCefetRJ/WeGIA/releases/tag/3.6.2mitrex_refsource_MISC
- github.com/LabRedesCefetRJ/WeGIA/security/advisories/GHSA-3r3q-8573-g3cqmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.