Stored Cross-Site Scripting Vulnerability in Windu CMS
CVE-2025-59115

5.3MEDIUM

Key Information:

Vendor

Jcd

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-59115?

Windu CMS has a security flaw in the login page that allows attackers to exploit stored cross-site scripting (XSS) vulnerabilities. This vulnerability arises from inadequate validation of user input, enabling malicious actors to inject arbitrary HTML and JavaScript code. When an administrator accesses the logs page, this injected content can be rendered and executed, potentially compromising sensitive information and administrative functionalities. Although Windu was notified of this issue, they have not provided details regarding vulnerable versions beyond the confirmed affected version 4.1. Other versions may also be at risk.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Windu CMS 0 <= 4.1

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.