Skip to main content

Vendor/product archive

thedaylightstudio / fuel_cms CVEs

Beta · best-effort

40 CVEs tagged to thedaylightstudio / fuel_cms11 Critical, 15 High, 14 Medium, 0 Low, 0 Unrated.

CVE-2026-30459

Published Apr 16, 2026

An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link p…

CVSS 7.1 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-30461

Published Apr 15, 2026

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_sub…

CVSS 8.3 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-30460

Published Apr 7, 2026

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

CVSS 8.8 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2026-30463

Published Mar 26, 2026

Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.

CVSS 7.7 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-30458

Published Mar 26, 2026

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2024-57605

Published Feb 12, 2025

Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-25369

Published Feb 22, 2024

A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-24950

Published Aug 11, 2023

SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to fun…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-22153

Published Jul 3, 2023

File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2020-22152

Published Jul 3, 2023

Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords o…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-22151

Published Jul 3, 2023

Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-33557

Published Jun 9, 2023

Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36570

Published Feb 3, 2023

Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-36569

Published Feb 3, 2023

Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-44117

Published Jun 10, 2022

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-28599

Published May 3, 2022

A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-38290

Published Aug 9, 2021

A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a ma…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2020-28705

Published Mar 10, 2021

FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /pages/delete/3.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-25 of 40 CVEsPage 1 of 2