Vulnerabilities
Vulnerable Software
Thedaylightstudio:  >> Fuel Cms  Security Vulnerabilities
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-04-07
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
CVSS Score
9.1
EPSS Score
0.0
Published
2026-03-26
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
CVSS Score
7.7
EPSS Score
0.0
Published
2026-03-26
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-03-26
Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.
CVSS Score
5.4
EPSS Score
0.002
Published
2025-02-12
A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.
CVSS Score
5.4
EPSS Score
0.001
Published
2024-02-22
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.
CVSS Score
8.8
EPSS Score
0.034
Published
2023-08-11
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
CVSS Score
9.8
EPSS Score
0.058
Published
2023-07-03
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
CVSS Score
5.4
EPSS Score
0.006
Published
2023-07-03
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
CVSS Score
9.8
EPSS Score
0.064
Published
2023-07-03


Contact Us

Shodan ® - All rights reserved