WeGIA, a web management platform for charitable institutions, patched two high-severity reflected cross-site scripting vulnerabilities affecting version 3.6.6 and earlier. The flaws, tracked as CVE-2026-33135 and CVE-2026-33136, allow attacker-controlled input to be reflected into HTML responses without sanitization or output encoding, creating a path to inject arbitrary JavaScript or HTML in a victim's browser.
The first issue affects novo_memorandoo.php via the sccs GET parameter, while the second affects listar_memorandos_ativos.php via the sccd GET parameter. In both cases, the vulnerable logic is triggered when the msg parameter is set to success, causing the application to concatenate untrusted input into an alert message rendered to users. Both bugs are classified as CWE-79 with a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N; WeGIA addressed them in version 3.6.7 and published related GitHub advisory, release, and remediation references.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
The two WeGIA reflected XSS vulnerabilities were publicly disclosed as CVE-2026-33135 and CVE-2026-33136, each classified as CWE-79 and assigned high-severity CVSS v3.1 scores. The disclosures describe impact on confidentiality and integrity and note that user interaction is required for exploitation.
The reflected XSS issues affecting WeGIA were remediated in version 3.6.7. References published with the disclosures point to associated GitHub advisory, release, and pull request materials.
Two reflected cross-site scripting vulnerabilities were identified in WeGIA: one in novo_memorandoo.php via the sccs parameter and another in listar_memorandos_ativos.php via the sccd parameter. Both flaws could allow arbitrary JavaScript or HTML injection in success-message responses.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.