WeGIA, a web management platform for charitable institutions, was found to contain two SQL-related vulnerabilities that could let attackers manipulate or fully compromise backend databases. CVE-2026-33134 affects version 3.6.5 and earlier in /html/matPat/restaurar_produto.php, where the id_produto parameter is incorporated into SQL queries without proper sanitization, enabling authenticated time-based blind SQL injection and arbitrary SQL command execution. The flaw carries a CVSS v3.1 vector of AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N and was fixed in version 3.6.6.
A second flaw, CVE-2026-33133, affects versions 3.6.5 and 3.6.6 in the loadBackupDB() function, which imports SQL files from uploaded backup archives without validating their contents. A privileged attacker can submit a crafted backup archive containing malicious SQL to create rogue administrator accounts, reset passwords, or perform other unauthorized database operations. The issue is tracked as CWE-89, was introduced in commit 370104c, and was patched in WeGIA version 3.6.7.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
WeGIA addressed CVE-2026-35395 in version 3.6.9, fixing a SQL injection flaw in dao/memorando/DespachoDAO.php where the id_memorando parameter from $_REQUEST was used in SQL queries without validation. The issue affected versions prior to 3.6.9 and allowed authenticated users to execute arbitrary SQL commands against the backend database.
On March 20, 2026, GitHub security advisories disclosed CVE-2026-33133 and CVE-2026-33134 affecting WeGIA. The advisories described a backup-archive arbitrary SQL execution flaw and an SQL injection issue in restaurar_produto.php, along with affected versions and fixed releases.
WeGIA released version 3.6.7 to fix CVE-2026-33133, an arbitrary SQL execution vulnerability in loadBackupDB() caused by importing SQL from uploaded backup archives without validating contents. The flaw affected versions 3.6.5 and 3.6.6 and could let a privileged attacker create rogue administrator accounts, change passwords, or perform other database operations.
WeGIA remediated CVE-2026-33134 in version 3.6.6 by fixing an SQL injection flaw in /html/matPat/restaurar_produto.php where the id_produto parameter was not properly sanitized. The issue affected version 3.6.5 and earlier and could allow arbitrary SQL command execution and database compromise.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.