CVE-2013-7473: Windu CMS

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.

Affected products

  • Windu Windu CMS: version 2.2 only

Published 2019-08-01. Last modified 2026-06-17.