216.73.216.197

CVE-2026-57309

· Published 20/07/2026 15:16 · Author: The MITRE Corporation

Labels: CVE-2026-57309

Essential information

Published
20/07/2026 15:16
Modified
Author
The MITRE Corporation
Creator
The MITRE Corporation
CVSS
9.3 CRITICAL (v4.0)
CISA KEV
No
CWE
CWE-89
CVSS vector

CVSS metrics

Description

A Blind SQL injection vulnerability has been identified in Windu CMS. A remote unauthenticated attacker is able to inject SQL syntax into URL path in HTTP header resulting in Blind SQL Injection. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.

NVD status

NVD
View on NVD