← Vulnerability feed

Vulnerability record · CVE-2025-27140 · published 24 February 2025

CVE-2025-27140: Wegia os command injection vulnerability

Wegia · Wegia

WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. The command is basically a command to move a temporary file, so a webshell upload is also possible. Version 3.2.15 contains a patch for the issue.

10.0 CVSS 4.0 Critical EPSS 2.9% · top 13.5% CWE-78 · OS command injectionCWE-284 · Improper access control
10.0CVSS 4.0 base score
2.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

WeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA application, `importar_dump.php` endpoint. This vulnerability could allow an attacker to execute arbitrary code remotely. The command is basically a command to move a temporary file, so a webshell upload is also possible. Version 3.2.15 contains a patch for the issue.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-27140 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-55169Wegia path traversal vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…EPSS 1.6%10.0CVE-2025-53823Wegia sql injection vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection…EPSS 0.47%10.0CVE-2025-53091Wegia sql injection vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Blind SQL Injection vulnerabili…EPSS 0.50%10.0CVE-2025-46828Wegia sql injection vulnerabilityWeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3…EPSS 0.55%10.0CVE-2025-30367Wegia sql injection vulnerabilityWeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter…EPSS 0.51%10.0CVE-2025-30364Wegia sql injection vulnerabilityWeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/ht…EPSS 0.66%10.0CVE-2025-26616Wegia path traversal vulnerabilityWeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …EPSS 0.68%10.0CVE-2025-26617Wegia sql injection vulnerabilityWeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A SQL Injection vulnerability was discovered in the W…EPSS 0.59%

Source: NIST National Vulnerability Database (record CVE-2025-27140), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.