CRITICAL 9.1 CVE-2026-54767 Published 17 Sept 2026

WeGIA Web Manager SQL Injection Vulnerability

Worried this affects your website?

WeGIA, a web manager for charitable institutions, is affected by an unauthenticated SQL injection vulnerability in version prior to 3.8.5.

The vulnerability exists in the web/html/socio/sistema/controller/deletar_socios.php file, which exposes a GET endpoint with a chave parameter.

An attacker can exploit this vulnerability by obtaining the hardcoded chave_correta value and using it to trigger TRUNCATE TABLE operations on the endereco, pessoafisica, pessoajuridica, and socio tables, permanently destroying member and contributor records.

The attack requires the affected tables to exist and the web process database account to possess truncation privileges.

This issue is fixed in version 3.8.5.

Reference: CVE-2026-54767 on NVD

← Back to Security News