Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-40283

25
FAUCET Score

CVE-2026-40283 is a Stored Cross-Site Scripting (XSS) vulnerability affecting WeGIA, a web-based management system for charitable institutions, in versions prior to 3.6.10. An authenticated user can inject malicious JavaScript through the "Nome" field on the "Informações Pacientes" page, with the payload persisting and executing each time patient information is accessed. The vulnerability has been patched in version 3.6.10. The vulnerability has a CVSS score of 6.8 (Medium severity) and requires high privileges to exploit, though it can be triggered remotely without user interaction. The primary impact is confidentiality compromise through information disclosure; however, the attack is limited to authenticated users with administrative or elevated permissions, which constrains the overall risk profile. There is no evidence of active exploitation in the wild, with an extremely low EPSS score of 0.000390000 indicating minimal real-world exploitation likelihood. No public exploit code is readily available, and the vulnerability remains relatively low in community attention, as indicated by its inactive status on threat lists. Organizations should prioritize upgrading to version 3.6.10, particularly if they manage sensitive patient data.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.6.10CPE matchmatch criteria
cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.8MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
NONE
Availability Impact
NONE
Exploitability Score
2.3
Impact Score
4.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.20%
Probability of exploitation in next 30 days
EPSS Percentile
10.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0020 is in the 6th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (1)

github_advisoryvendor investigatingvia nvd_reference
View patch

References

github.com / LabRedesCefetRJ/WeGIA/security/advisories/GHSA-x74c-gwj9-6cwr
ExploitVendor Advisory