{"id":82285,"date":"2026-07-20T16:46:56","date_gmt":"2026-07-20T13:16:56","guid":{"rendered":"https:\/\/afaghhosting.net\/blog\/cve-2026-57311-unrestricted-upload-of-file-with-dangerous-type-in-windu-cms\/"},"modified":"2026-07-20T16:46:56","modified_gmt":"2026-07-20T13:16:56","slug":"cve-2026-57311-unrestricted-upload-of-file-with-dangerous-type-in-windu-cms","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/cve-2026-57311-unrestricted-upload-of-file-with-dangerous-type-in-windu-cms\/","title":{"rendered":"CVE-2026-57311 &#8211; Unrestricted Upload of File with Dangerous Type in Windu CMS"},"content":{"rendered":"<p>CVE ID :CVE-2026-57311<\/p>\n<p>  Published : July 20, 2026, 1:16 p.m. | 26\u00a0minutes ago<\/p>\n<p>  Description :Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary\u00a0files, including PHP. This can lead to Remote Code Execution.<\/p>\n<p>Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may also affect other versions.<\/p>\n<p>  Severity: 5.3 | MEDIUM<\/p>\n<p>  Visit the link for more details, such as CVSS details, affected products, timeline, and more&#8230;\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>CVE ID :CVE-2026-57311 Published : July 20, 2026, 1:16 p.m. | 26\u00a0minutes ago Description :Windu CMS does not validate types of uploaded files. An authenticated attacker can upload arbitrary\u00a0files, including PHP. This can lead to Remote Code Execution. Because vendor contact attempts were unsuccessful, the vulnerability has only been confirmed in version 4.1 but may &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-82285","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=82285"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/82285\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=82285"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=82285"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=82285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}