CVE-2026-57310

Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to decode user credentials. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
CVSS

No CVSS.

Configurations

No configuration.

History

20 Jul 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-20 13:16

Updated : 2026-07-22 20:50


NVD link : CVE-2026-57310

Mitre link : CVE-2026-57310

CVE.ORG link : CVE-2026-57310


JSON object : View

Products Affected

No product.

CWE
CWE-916

Use of Password Hash With Insufficient Computational Effort