CERT Polska disclosed three vulnerabilities in JCD Windu CMS affecting confirmed version 4.1, warning that other versions may also be impacted. The issues include CVE-2026-57309, a blind SQL injection mapped to CWE-89 that can be exploited remotely without authentication by injecting SQL syntax into a URL path carried in an HTTP header, and CVE-2026-57310, a password storage weakness mapped to CWE-916 caused by the use of MD5 and SHA1 with a static salt.
The advisory also details CVE-2026-57311, an unrestricted file upload flaw that allows an authenticated attacker to upload arbitrary files, including PHP, resulting in remote code execution. CERT Polska said it coordinated disclosure of the vulnerabilities and credited Jakub Lipiński, Marek Tołczyk, and Kamil Królikowski with the responsible report, underscoring the risk of database compromise, credential exposure, and server takeover in affected Windu CMS deployments.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
On 2026-07-20, CERT Polska published its coordinated disclosure advisory for the three Windu CMS vulnerabilities. The notice described unauthenticated blind SQL injection, insufficient password hashing effort, and unrestricted file upload issues.
CERT Polska confirmed three vulnerabilities in JCD Windu CMS version 4.1: CVE-2026-57309 blind SQL injection, CVE-2026-57310 weak password hashing with MD5 and SHA1 plus a static salt, and CVE-2026-57311 unrestricted file upload leading to possible remote code execution. The advisory noted other versions may also be affected.
CERT Polska said it received a responsible report about three vulnerabilities affecting JCD Windu CMS and participated in coordinated disclosure. The report was credited to Jakub Lipiński, Marek Tołczyk, and Kamil Królikowski.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cert.pl
Open sourcecwe.mitre.org
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.