CVE-2026-57309

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 13:16

Updated : 2026-07-22 20:53


NVD link : CVE-2026-57309

Mitre link : CVE-2026-57309

CVE.ORG link : CVE-2026-57309


JSON object : View

Products Affected

No product.

CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')