Vulnerability Details CVE-2025-53929
WeGIA is an open source web manager with a focus on the Portuguese language and charitable institutions. A Stored Cross-Site Scripting (XSS) vulnerability was identified in the `adicionar_cor.php` endpoint of the WeGIA application prior to version 3.4.5. This vulnerability allows attackers to inject malicious scripts into the `cor` parameter. The injected scripts are stored on the server and executed automatically whenever the affected page `cadastro_pet.php` is accessed by users, posing a significant security risk. Version 3.4.5 fixes the issue.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 19.6%
CVSS Severity
CVSS v3 Score 5.4
Products affected by CVE-2025-53929
-
cpe:2.3:a:wegia:wegia:0.9.4
-
cpe:2.3:a:wegia:wegia:1.0
-
cpe:2.3:a:wegia:wegia:2.0
-
cpe:2.3:a:wegia:wegia:3.0
-
cpe:2.3:a:wegia:wegia:3.1
-
cpe:2.3:a:wegia:wegia:3.2.0
-
cpe:2.3:a:wegia:wegia:3.2.10
-
cpe:2.3:a:wegia:wegia:3.2.11
-
cpe:2.3:a:wegia:wegia:3.2.12
-
cpe:2.3:a:wegia:wegia:3.2.13
-
cpe:2.3:a:wegia:wegia:3.2.14
-
cpe:2.3:a:wegia:wegia:3.2.15
-
cpe:2.3:a:wegia:wegia:3.2.16
-
cpe:2.3:a:wegia:wegia:3.2.17
-
cpe:2.3:a:wegia:wegia:3.2.6
-
cpe:2.3:a:wegia:wegia:3.2.7
-
cpe:2.3:a:wegia:wegia:3.2.8
-
cpe:2.3:a:wegia:wegia:3.2.9
-
cpe:2.3:a:wegia:wegia:3.3.0
-
cpe:2.3:a:wegia:wegia:3.3.1
-
cpe:2.3:a:wegia:wegia:3.3.2
-
cpe:2.3:a:wegia:wegia:3.3.3
-
cpe:2.3:a:wegia:wegia:3.4.0
-
cpe:2.3:a:wegia:wegia:3.4.1
-
cpe:2.3:a:wegia:wegia:3.4.2