Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Marek Tołczyk

#13747of 56,330
20.9Total CVSS
Vulnerabilities · 3
Medium
2
Critical
1
PT-2026-61587
9.3
2026-07-20
Jcd · Windu Cms · CVE-2026-57309
A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
PT-2026-61588
6.3
2026-07-20
Jcd · Windu Cms · CVE-2026-57310
Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
PT-2026-61589
5.3
2026-07-20
Windu Cms · Windu Cms · CVE-2026-57311
**Name of the Vulnerable Software and Affected Versions** Windu CMS version 4.1 **Description** An authenticated attacker can upload arbitrary files, including PHP scripts, because the system does not validate the types of uploaded files. This flaw can lead to Remote Code Execution (RCE), which allows an attacker to execute arbitrary commands on the server. There have been reports of elevated activities targeting this software. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.