Medium severity4.8OSV Advisory· Published Dec 13, 2018· Updated Jun 17, 2026
CVE-2018-20136
CVE-2018-20136
Description
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: 1.0.3, 1.0.4, 1.0.5, …
- cpe:2.3:a:thedaylightstudio:fuel_cms:1.4.3:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
1- github.com/CCCCCrash/POCs/tree/master/Web/fuel-cms/xss2nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.