Windu CMS has a vulnerability that allows authenticated attackers to upload arbitrary files, including PHP, due to lack of file type validation. This can lead to Remote Code Execution. The vulnerability has been confirmed in version 4.1, but may also affect other versions. Users should be cautious and take necessary actions to secure their installations, especially if using version 4.1 or similar configurations.
CVE-2026-57310 involves Windu CMS's use of weak MD5 and SHA1 hashing algorithms with a static salt for storing user passwords. This implementation allows an attacker who obtains the password hash to potentially decode user credentials. The vulnerability has been confirmed in version 4.1, but may affect other versions due to limited information. Successful exploitation requires access to the hashed passwords.
A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. The vulnerability has only been confirmed in version 4.1 but may also affect other versions. This issue is critical due to its potential for data exposure or manipulation. Users and administrators of Windu CMS sh [truncated]