CVE-2025-53529 | WeGIA allows SQL Injection in html/funcionario/profile_funcionario.php (id_funcionario parameter)
Exp
WeGIA is a web manager for charitable institutions. An SQL Injection vulnerability was identified in the /html/funcionario/profile_funcionario.php endpoint. The id_funcionario parameter is not properly sanitized or validated before being used in a SQL query, allowing an unauthenticated attacker to inject arbitrary SQL commands. The vulnerability is fixed in 3.4.3.
Conclusion & alert: CVE-2025-53529 is rated High Exploit Risk (78.8/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 0.61%).Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB).Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Public exploit references (Exploit-DB) for CVE-2025-53529
Exploit prediction scoring system (EPSS) score for CVE-2025-53529
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).