| CVE ID | CVE-2026-57309 |
| Publication date | 20 July 2026 |
| Vendor | JCD |
| Product | Windu CMS |
| Vulnerable versions | 4.1 |
| Vulnerability type (CWE) | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') (CWE-89) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-57310 |
| Publication date | 20 July 2026 |
| Vendor | JCD |
| Product | Windu CMS |
| Vulnerable versions | 4.1 |
| Vulnerability type (CWE) | Use of Password Hash With Insufficient Computational Effort (CWE-916) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-57311 |
| Publication date | 20 July 2026 |
| Vendor | JCD |
| Product | Windu CMS |
| Vulnerable versions | 4.1 |
| Vulnerability type (CWE) | Unrestricted Upload of File with Dangerous Type (CWE-434) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in Windu CMS software and participated in coordination of their disclosure.
The vulnerability CVE-2026-57309: A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in a successful attack.
The vulnerability CVE-2026-57310: Windu CMS uses hashing algorithm based on MD5 and SHA1 with static salt to store user passwords. This allows an attacker who obtain password hash to crack it and recover user credentials.
The vulnerability CVE-2026-57311: Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution.
The vulnerabilities have only been confirmed in version 4.1 but may also affect other versions.
Credits
We thank Jakub Lipiński, Marek Tołczyk and Kamil Królikowski for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.