Vulnerability index

Browse CVEs

37 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.1 CVE-2026-30459 An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a vi… Fuel Cms No fix yet Fix from $1,9502026-04-16 HIGH 8.3 CVE-2026-30461 Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.ph… Fuel Cms No fix yet Fix from $1,9502026-04-15 HIGH 8.8 CVE-2026-30460 Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. Fuel Cms No fix yet Fix from $1,9502026-04-07 CRITICAL 9.1 CVE-2026-30458 An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. Fuel Cms No fix yet Fix from $2,3002026-03-26 HIGH 7.7 CVE-2026-30463 Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component. Fuel Cms No fix yet Fix from $1,9502026-03-26 CRITICAL 9.8 CVE-2026-30457 An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. Dwoo Mitigation only Fix from $2,3002026-03-26 MEDIUM 5.4 CVE-2024-57605 Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/page… Fuel Cms No fix yet Fix from $1,6002025-02-12 MEDIUM 5.4 CVE-2024-25369 A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id pa… Fuel Cms No fix yet Fix from $1,6002024-02-22 HIGH 8.8 CVE-2020-24950 SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary cod… Fuel Cms No fix yet Fix from $1,9502023-08-11 CRITICAL 9.8 CVE-2020-22151 Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests parameter of t… Fuel Cms No fix yet Fix from $2,3002023-07-03 CRITICAL 9.8 CVE-2020-22153 File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in t… Fuel Cms No fix yet Fix from $2,3002023-07-03 MEDIUM 5.4 CVE-2020-22152 Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote attacker to execute arbitrary code via the page title, meta d… Fuel Cms No fix yet Fix from $1,6002023-07-03 HIGH 8.8 CVE-2023-33557 Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php. Fuel Cms No fix yet Fix from $1,9502023-06-09 HIGH 8.8 CVE-2021-36569 Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2. Fuel Cms Patch available Fix from $1,9502023-02-03 HIGH 8.8 CVE-2021-36570 Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---. Fuel Cms Patch available Fix from $1,9502023-02-03 HIGH 8.8 CVE-2021-44117 A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4. Fuel Cms No fix yet Fix from $1,9502022-06-10 MEDIUM 5.4 CVE-2022-28599 A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which ac… Fuel Cms No fix yet Fix from $1,6002022-05-03 MEDIUM 5.4 CVE-2022-27156 Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection. Fuel Cms Patch available Fix from $1,6002022-04-11 MEDIUM 5.4 CVE-2021-44607 A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file. Fuel Cms No fix yet Fix from $1,6002022-02-24 CRITICAL 9.8 CVE-2021-38727 FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items Fuel Cms No fix yet Fix from $2,3002021-09-09 HIGH 8.8 CVE-2021-38723 FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items Fuel Cms No fix yet Fix from $1,9502021-09-09 MEDIUM 6.5 CVE-2021-38721 FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability Fuel Cms Patch available Fix from $1,6002021-09-09 MEDIUM 5.3 CVE-2021-38725 Fuel CMS 1.5.0 has a brute force vulnerability in fuel/modules/fuel/controllers/Login.php Fuel Cms Patch available Fix from $1,6002021-09-09 HIGH 8.1 CVE-2021-38290 A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset… Fuel Cms after 1.5.0 Fix from $1,9502021-08-09 CRITICAL 9.8 CVE-2020-24791 FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromi… Fuel Cms No fix yet Fix from $2,3002021-03-10 HIGH 8.8 CVE-2020-23722 An issue was discovered in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id… Fuel Cms No fix yet Fix from $1,9502021-03-10 MEDIUM 5.4 CVE-2020-23721 An issue was discovered in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english. Fuel Cms No fix yet Fix from $1,6002021-03-10 CRITICAL 9.8 CVE-2020-26045 FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise t… Fuel Cms No fix yet Fix from $2,3002021-01-05 MEDIUM 5.4 CVE-2020-26046 FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerabilit… Fuel Cms No fix yet Fix from $1,6002021-01-05 CRITICAL 9.8 CVE-2020-26167 In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrato… Fuel Cms after 1.4.12 Fix from $2,3002020-11-04