CVE-2026-57309

Severity CVSS v4.0:
CRITICAL
Type:
CWE-89 SQL Injection
Publication date:
20/07/2026
Last modified:
22/07/2026

Description

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection.<br /> <br /> Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

References to Advisories, Solutions, and Tools