CVE-2025-26615
WeGIA is an open source Web Manager for Institutions with a focus on Portuguese language users. A Path Traversal vulnerability was discovered in the WeGIA application, `examples.php` endpoint. This vulnerability could allow an attacker to gain unauthorized access to sensitive information stored in `config.php`. `config.php` contains information that could allow direct access to the database. This issue has been addressed in version 3.2.14 and all users are advised to upgrade. There are no known workarounds for this vulnerability.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
- EPSS probability
- 0.75%
- CWE
- CWE-22, CWE-284
- Published
- 2025-02-18
- Last modified
- 2026-03-13
Affected products
- LabRedesCefetRJ WeGIA
Weakness type
Related vulnerabilities
- CVE-2026-81789 — WordPress Advanced Product Fields Extended for WooCommerce plugin <= 3.1.6 - Arbitrary File Deletion vulnerability
- CVE-2026-81275 — WordPress Youzify plugin <= 1.3.7 - Arbitrary File Download vulnerability
- CVE-2026-88790 — proma-ai Proma File Preview Service file-preview-service.ts resolveTargetPath path traversal
- CVE-2026-64838 — ICEcoder through 8.1 Path Traversal via oldFileName Parameter
- CVE-2026-64836 — ICEcoder through 8.1 Path Traversal via Ineffective File::check() Confinement
- CVE-2026-9166 — LFI in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-78085 — Joomla Extension - joomshaper.com - Path Traversal in Gallery Image Management in SP Property < 4.1.4
- CVE-2026-15019 — Direct Download for WooCommerce <= 1.19 - Unauthenticated Arbitrary File Read via 'file_id' Path Segment