Stored Cross-Site Scripting Vulnerability in Windu CMS
CVE-2025-59115
What is CVE-2025-59115?
Windu CMS has a security flaw in the login page that allows attackers to exploit stored cross-site scripting (XSS) vulnerabilities. This vulnerability arises from inadequate validation of user input, enabling malicious actors to inject arbitrary HTML and JavaScript code. When an administrator accesses the logs page, this injected content can be rendered and executed, potentially compromising sensitive information and administrative functionalities. Although Windu was notified of this issue, they have not provided details regarding vulnerable versions beyond the confirmed affected version 4.1. Other versions may also be at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Windu CMS 0 <= 4.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
