Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 29, 2026
Unrestricted Upload of File with Dangerous Type in Windu CMS
CVE-2026-57311
Description
Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary files, including PHP. This can lead to Remote Code Execution.
Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- cert.pl/posts/2026/07/CVE-2026-57309mitrethird-party-advisory
- windu.orgmitreproduct
News mentions
0No linked articles in our index yet.