Windu Cms · Windu Cms · CVE-2026-57311
**Name of the Vulnerable Software and Affected Versions**
Windu CMS version 4.1
**Description**
An authenticated attacker can upload arbitrary files, including PHP scripts, because the system does not validate the types of uploaded files. This flaw can lead to Remote Code Execution (RCE), which allows an attacker to execute arbitrary commands on the server. There have been reports of elevated activities targeting this software.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.