ZeroHour

Vulnerabilities

40 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-30459
An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user v

An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message.

NVD description · AI analysis pending
7.1<1% PoC
  • thedaylightstudio fuel cms
CVE-2026-30461
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the f

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_submodule.

NVD description · AI analysis pending
8.3<1% PoC
  • thedaylightstudio fuel cms
CVE-2026-30460
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

NVD description · AI analysis pending
8.8<1% PoC
  • thedaylightstudio fuel cms
CVE-2026-30458
+1 in the same advisory: …30463
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

NVD description · AI analysis pending
9.1
group max
<1% PoC
  • thedaylightstudio fuel cms
CVE-2026-30457
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

NVD description · AI analysis pending
9.8<1% PoC
  • thedaylightstudio dwoo
  • thedaylightstudio fuel cms
CVE-2024-57605
Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages component

Cross Site Scripting vulnerability in Daylight Studio Fuel CMS v.1.5.2 allows an attacker to escalate privileges via the /fuel/blocks/ and /fuel/pages components.

NVD description · AI analysis pending
5.4<1% PoC
  • thedaylightstudio fuel cms
CVE-2024-25369
A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.

A reflected Cross-Site Scripting (XSS) vulnerability in FUEL CMS 1.5.2allows attackers to run arbitrary code via crafted string after the group_id parameter.

NVD description · AI analysis pending
5.4<1% PoC
  • thedaylightstudio fuel cms
CVE-2020-24950
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the c

SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbitrary code via the col parameter to function list_items.

NVD description · AI analysis pending
8.81% PoC
  • thedaylightstudio fuel cms
CVE-2020-22153
+2 in the same advisory: …22151 …22152
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigati

File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.

NVD description · AI analysis pending
9.8
group max
1% PoC
  • thedaylightstudio fuel cms
CVE-2023-33557
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.

Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.

NVD description · AI analysis pending
8.8<1% PoC ×2
  • thedaylightstudio fuel cms
CVE-2021-36570
+1 in the same advisory: …36569
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.

Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete/2---.

NVD description · AI analysis pending
8.8<1% PoC
  • thedaylightstudio fuel cms
CVE-2021-44117
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.

NVD description · AI analysis pending
8.81% PoC
  • thedaylightstudio fuel cms
CVE-2022-28599
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a sto

A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.

NVD description · AI analysis pending
5.4<1% PoC
  • thedaylightstudio fuel cms
CVE-2022-27156
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.

Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.

NVD description · AI analysis pending
5.4<1% PoC
  • thedaylightstudio fuel cms
CVE-2021-44607
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.

A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.

NVD description · AI analysis pending
5.4<1% PoC
  • thedaylightstudio fuel cms
CVE-2021-38727
+3 in the same advisory: …38723 …38721 …38725
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items

FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items

NVD description · AI analysis pending
9.8
group max
2% PoC
  • thedaylightstudio fuel cms
CVE-2021-38290
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php.

A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/libraries/Asset.php. An attacker can use a man in the middle attack such as phishing.

NVD description · AI analysis pending
8.11% PoC
  • thedaylightstudio fuel cms
CVE-2020-24791
+3 in the same advisory: …23722 …23721 …28705
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1.

FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

NVD description · AI analysis pending
9.8
group max
3% PoC ×3
  • thedaylightstudio fuel cms
CVE-2020-26045
+1 in the same advisory: …26046
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/.

FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.

NVD description · AI analysis pending
9.8
group max
2% PoC
  • thedaylightstudio fuel cms
CVE-2020-26167
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.

In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an administrator one.

NVD description · AI analysis pending
9.83%
  • thedaylightstudio fuel cms
CVE-2020-17463
Unauthenticated SQL Injection in FUEL CMS 1.4.7

CVE-2020-17463 is a SQL injection flaw (CWE-89) in FUEL CMS 1.4.7, exploitable through the 'col' parameter on the /pages/items, /permissions/items, and /navigation/items endpoints. Because the parameter is not properly sanitized, a remote, unauthenticated attacker can inject arbitrary SQL via crafted HTTP requests to these URLs with no user interaction or privileges required. Successful exploitation can expose or alter the contents of the CMS database, and under some database configurations may enable further attacks against the backend. Any installation running FUEL CMS 1.4.7 is affected, with internet-exposed instances at greatest risk. The flaw carries a critical CVSS 3.1 score of 9.8, a top-percentile EPSS score (89.7% probability of exploitation within 30 days), a public proof-of-concept, and was added to CISA's Known Exploited Vulnerabilities Catalog on 2021-12-10, indicating known in-the-wild exploitation; ransomware association is unknown.

Do: Upgrade FUEL CMS to a release newer than 1.4.7 per the vendor's instructions, as required by the CISA KEV catalog entry. If patching is not immediate, restrict or filter the 'col' parameter on /pages/items, /permissions/items, and /navigation/items (e.g., via WAF rules) and confirm the CMS database account follows least-privilege principles. Review web and database logs for anomalous queries or SQL injection payloads targeting these endpoints, and verify internet-exposed instances are patched given the KEV listing and high EPSS score.

9.890% KEV PoC
  • thedaylightstudio (Daylight Studio) FUEL CMS 1.4.7 (version cited in the advisory; CISA lists FUEL CMS as the affected product without a broader stated range)
nichelikely low thousands of internet-exposed installations (estimate; no authoritative install count in source data)
CVE-2019-15229
+1 in the same advisory: …15228
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console.

FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console. This could lead to an attacker tricking the administrator into executing arbitrary code via a specially crafted HTML page.

NVD description · AI analysis pending
8.8
group max
<1% PoC ×2
  • thedaylightstudio fuel cms
CVE-2018-20188
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

NVD description · AI analysis pending
8.8<1% PoC
  • thedaylightstudio fuel cms
CVE-2018-20137
+1 in the same advisory: …20136
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=englis

XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.

NVD description · AI analysis pending
4.8<1% PoC
  • thedaylightstudio fuel cms
CVE-2018-16763
+1 in the same advisory: …16762
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

NVD description · AI analysis pending
9.883% PoC ×5
  • thedaylightstudio fuel cms
CVE-2018-16416
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.

Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrator's password.

NVD description · AI analysis pending
8.8<1% PoC ×2
  • thedaylightstudio fuel cms