User Enumeration Vulnerability in Windu CMS
CVE-2025-59116

6.9MEDIUM

Key Information:

Vendor

Jcd

Status
Vendor
CVE Published:
18 November 2025

What is CVE-2025-59116?

Windu CMS has a security flaw that allows user enumeration during the login process. By providing subtle differences in feedback messages, attackers can ascertain whether a username exists within the system. This vulnerability poses a risk of brute force attacks, as it may give malicious actors the ability to identify valid usernames and target them for unauthorized access. The vendor was informed but has not disclosed the full range of affected versions, although version 4.1 has been confirmed to be vulnerable.

Affected Version(s)

Windu CMS 4.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Karol Czubernat
.
CVE-2025-59116 : User Enumeration Vulnerability in Windu CMS