← Vulnerability feed

Vulnerability record · CVE-2025-61665 · published 2 October 2025

CVE-2025-61665: Wegia information exposure vulnerability

Wegia · Wegia

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers to directly access sensitive personal and financial information of members without requiring authentication or authorization. This issue is fixed in version 3.5.0.

8.7 CVSS 4.0 High EPSS 0.48% · top 61.5% CWE-200 · Information exposureCWE-287 · Improper authentication
8.7CVSS 4.0 base score
0.48%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

WeGIA is an open source web manager with a focus on charitable institutions. Versions 3.4.12 and below contain a Broken Access Control vulnerability, identified in the get_relatorios_socios.php endpoint. This vulnerability allows unauthenticated attackers to directly access sensitive personal and financial information of members without requiring authentication or authorization. This issue is fixed in version 3.5.0.

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-61665 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-55169Wegia path traversal vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Prior to version 3.4.8, a path traversal vul…EPSS 1.6%10.0CVE-2025-53823Wegia sql injection vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. Versions prior to 3.4.5 have a SQL Injection…EPSS 0.47%10.0CVE-2025-53091Wegia sql injection vulnerabilityWeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Time-Based Blind SQL Injection vulnerabili…EPSS 0.50%10.0CVE-2025-46828Wegia sql injection vulnerabilityWeGIA is a web manager for charitable institutions. An unauthenticated SQL Injection vulnerability was identified in versions up to and including 3.3…EPSS 0.55%10.0CVE-2025-30367Wegia sql injection vulnerabilityWeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.6 in the nextPage parameter…EPSS 0.50%10.0CVE-2025-30364Wegia sql injection vulnerabilityWeGIA is a Web manager for charitable institutions. A SQL Injection vulnerability was identified in versions prior to 3.2.8 in the endpoint /WeGIA/ht…EPSS 0.65%10.0CVE-2025-27140Wegia os command injection vulnerabilityWeGIA is a Web manager for charitable institutions. An OS Command Injection vulnerability was discovered in versions prior to 3.2.15 of the WeGIA app…EPSS 2.9%10.0CVE-2025-26616Wegia path traversal vulnerabilityWeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the …EPSS 0.68%

Source: NIST National Vulnerability Database (record CVE-2025-61665), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.