Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6673
Adobe 6383
Ibm 6286
Cisco 5751
Debian 3919
Mozilla 2886
Apache 2864
Redhat 2586
MEDIUM 5.3
CVE-2025-59116
Windu CMS is vulnerable to User Enumeration. This issue occurs during logon, where a difference in messages could allow an attacker to determine if t…
Windu Cms
Mitigation only
HIGH 7.5
CVE-2025-59113
Windu CMS implements weak client-side brute-force protection by using parameter loginError. Information about attempt count or timeout is not stored …
Windu Cms
Mitigation only
MEDIUM 6.5
CVE-2025-59112
Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Malicious attacker can craft special website, which when visited…
Windu Cms
Mitigation only
MEDIUM 6.5
CVE-2025-59114
Windu CMS is vulnerable to Cross-Site Request Forgery in file uploading functionality. Malicious attacker can craft special website, which when visit…
Windu Cms
Mitigation only
MEDIUM 5.4
CVE-2025-59115
Windu CMS is vulnerable to Stored Cross-Site Scripting (XSS) in the logon page where input data has no proper validation. Malicious attacker can inje…
Windu Cms
Mitigation only
MEDIUM 6.5
CVE-2025-59110
Windu CMS is vulnerable to Cross-Site Request Forgery in user editing functionality. Implemented CSRF protection mechanism can be bypassed by using C…
Windu Cms
Mitigation only
MEDIUM 6.5
CVE-2025-59111
Windu CMS is vulnerable to Broken Access Control in user editing functionality. Malicious attacker can send a GET request which allows privileged use…
Windu Cms
Mitigation only
HIGH 8.8
CVE-2013-7473
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
Windu Cms
No fix yet
MEDIUM 6.1
CVE-2013-7474
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
Windu Cms
No fix yet