FuelCMS
Source repositories
CVEs (27)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-16763 | Cri | 0.73 | 9.8 | 0.83 | Sep 9, 2018 | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution. | ||
| CVE-2026-30457 | Cri | 0.64 | 9.8 | 0.01 | Mar 26, 2026 | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. | ||
| CVE-2021-38727 | Cri | 0.64 | 9.8 | 0.02 | Sep 9, 2021 | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items | ||
| CVE-2020-24791 | Cri | 0.64 | 9.8 | 0.03 | Mar 10, 2021 | FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. | ||
| CVE-2018-16762 | Cri | 0.64 | 9.8 | 0.01 | Sep 9, 2018 | FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items. | ||
| CVE-2026-30458 | Cri | 0.59 | 9.1 | 0.00 | Mar 26, 2026 | An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. | ||
| CVE-2026-30460 | Hig | 0.57 | 8.8 | 0.01 | Apr 7, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. | ||
| CVE-2021-38723 | Hig | 0.57 | 8.8 | 0.01 | Sep 9, 2021 | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items | ||
| CVE-2020-23722 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2021 | An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters. | ||
| CVE-2019-15229 | Hig | 0.57 | 8.8 | 0.01 | Aug 20, 2019 | FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page. | ||
| CVE-2018-20188 | Hig | 0.57 | 8.8 | 0.01 | Dec 17, 2018 | FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account. | ||
| CVE-2018-16416 | Hig | 0.57 | 8.8 | 0.01 | Sep 3, 2018 | Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password. | ||
| CVE-2026-30461 | Hig | 0.54 | 8.3 | 0.01 | Apr 15, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule. | ||
| CVE-2026-30463 | Hig | 0.50 | 7.7 | 0.00 | Mar 26, 2026 | Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component. | ||
| CVE-2026-30459 | Hig | 0.46 | 7.1 | 0.00 | Apr 16, 2026 | An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message. | ||
| CVE-2026-38948 | Med | 0.35 | 5.4 | 0.00 | Apr 28, 2026 | Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code. | ||
| CVE-2024-57605 | Med | 0.35 | 5.4 | 0.00 | Feb 12, 2025 | Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components. | ||
| CVE-2020-22152 | Med | 0.35 | 5.4 | 0.01 | Jul 3, 2023 | Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function. | ||
| CVE-2022-27156 | Med | 0.35 | 5.4 | 0.00 | Apr 11, 2022 | Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection. | ||
| CVE-2021-44607 | Med | 0.35 | 5.4 | 0.00 | Feb 24, 2022 | A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file. |
- risk 0.73cvss 9.8epss 0.83
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
- risk 0.64cvss 9.8epss 0.01
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
- risk 0.64cvss 9.8epss 0.02
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
- risk 0.64cvss 9.8epss 0.03
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
- risk 0.64cvss 9.8epss 0.01
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.
- risk 0.59cvss 9.1epss 0.00
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
- risk 0.57cvss 8.8epss 0.01
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
- risk 0.57cvss 8.8epss 0.01
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
- risk 0.57cvss 8.8epss 0.01
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.
- risk 0.57cvss 8.8epss 0.01
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
- risk 0.57cvss 8.8epss 0.01
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.
- risk 0.54cvss 8.3epss 0.01
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.
- risk 0.50cvss 7.7epss 0.00
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
- risk 0.46cvss 7.1epss 0.00
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.
- risk 0.35cvss 5.4epss 0.00
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.
- risk 0.35cvss 5.4epss 0.00
Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.
- risk 0.35cvss 5.4epss 0.01
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
- risk 0.35cvss 5.4epss 0.00
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.
- risk 0.35cvss 5.4epss 0.00
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.
Page 1 of 2