SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-57309

CRITICAL · CVSS 9.3 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

Windu CMS is vulnerable to a Blind SQL Injection attack that allows remote unauthenticated attackers to inject SQL syntax through the URL path in the HTTP header. This could lead to unauthorized access to sensitive data or manipulation of the database. Organizations using Windu CMS, particularly version 4.1 and potentially other versions, should prioritize addressing this vulnerability to mitigate the risk of data breaches.

CVE
CVE-2026-57309
Severity
CRITICAL
CVSS
9.3
EPSS
0.31%

Original NVD Description

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.