Vulnerability index

Browse CVEs

9 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Windu Cms MEDIUM 5.3
CVE-2025-59116

Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if t…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms HIGH 7.5
CVE-2025-59113

Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored …

Mitigation only
Fix from $1,950 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59112

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59114

Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visit…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms MEDIUM 5.4
CVE-2025-59115

Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation. Malicious attacker can inje…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59110

Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using C…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms MEDIUM 6.5
CVE-2025-59111

Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET request which allows privileged use…

Mitigation only
Fix from $1,600 2025-11-18
Windu Cms HIGH 8.8
CVE-2013-7473

Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

No fix yet
Fix from $1,950 2019-08-01
Windu Cms MEDIUM 6.1
CVE-2013-7474

Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.

No fix yet
Fix from $1,600 2019-08-01