CVE-2026-33136 is a Reflected Cross-Site Scripting (XSS) vulnerability affecting WeGIA web manager versions 3.6.6 and below. An unauthenticated attacker can inject arbitrary JavaScript or HTML into the sccd GET parameter of the listar_memorandos_ativos.php endpoint, which is then echoed without sanitization. Rated Medium severity (CVSS 6.1), exploitation requires user interaction via a malicious link and could lead to low confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code, or widespread community attention for this vulnerability, with its EPSS score indicating a very low probability of exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.7CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.