CVE-2026-40283 is a Stored Cross-Site Scripting (XSS) vulnerability affecting WeGIA, a web-based management system for charitable institutions, in versions prior to 3.6.10. An authenticated user can inject malicious JavaScript through the "Nome" field on the "Informações Pacientes" page, with the payload persisting and executing each time patient information is accessed. The vulnerability has been patched in version 3.6.10. The vulnerability has a CVSS score of 6.8 (Medium severity) and requires high privileges to exploit, though it can be triggered remotely without user interaction. The primary impact is confidentiality compromise through information disclosure; however, the attack is limited to authenticated users with administrative or elevated permissions, which constrains the overall risk profile. There is no evidence of active exploitation in the wild, with an extremely low EPSS score of 0.000390000 indicating minimal real-world exploitation likelihood. No public exploit code is readily available, and the vulnerability remains relatively low in community attention, as indicated by its inactive status on threat lists. Organizations should prioritize upgrading to version 3.6.10, particularly if they manage sensitive patient data.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.6.10CPE matchmatch criteria | cpe:2.3:a:wegia:wegia:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.