Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-57309: Windu CMS SQL Injection in URL Path
CVE-2026-57309
CVE-2026-57309
Summary
Windu CMS versions, including 4.1, are at risk of SQL injection attacks. An attacker can inject malicious SQL code into the URL, potentially stealing sensitive data or disrupting the website. Update to the latest version or contact the vendor for assistance.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| jcd | windu cms | 4.1 |
Original title
Blind SQL Injection in Windu CMS
Original description
A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
nvd CVSS4.0
9.3
Vulnerability type
CWE-89
SQL Injection
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026