Skip to main content

CWE archive

CWE-473 CVEs

Programmatic archive

5 CVEs tagged with CWE-4732 Critical, 2 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-40285

Published Apr 17, 2026

WeGIA is a web manager for charitable institutions. Versions prior to 3.6.10 contain a SQL injection vulnerability in dao/memorando/UsuarioDAO.php. The cpf_usuario POST parameter…

CVSS 8.8 · High
evidence mentions
1
Buzz score
11.9

CVE-2026-28411

Published Feb 27, 2026

WeGIA is a web manager for charitable institutions. Prior to version 3.6.5, an unsafe use of the `extract()` function on the `$_REQUEST` superglobal allows an unauthenticated atta…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2024-27489

Published Jul 19, 2024

An issue in the DelFile() function of WMCMS v4.4 allows attackers to delete arbitrary files via a crafted POST request.

CVSS 7.5 · High

CVE-2023-36845

Published Aug 17, 2023

A PHP External Variable Modification vulnerability in J-Web of Juniper Networks Junos OS on EX Series and SRX Series allows an unauthenticated, network-based attacker to remot…

CVSS 9.8 · Critical
evidence mentions
14
Buzz score
61.6
KEV listed
Showing 1-5 of 5 CVEsPage 1 of 1