Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thedaylightstudio fuel cms vulnerabilities and exploits
(subscribe to this query)
NA
CVE-2023-33557
Fuel CMS v1.5.2 exists to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
Thedaylightstudio Fuel Cms 1.5.2
NA
CVE-2020-22152
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote malicious user to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
Thedaylightstudio Fuel Cms 1.4.6
605
VMScore
CVE-2018-20188
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
Thedaylightstudio Fuel Cms 1.4.3
312
VMScore
CVE-2022-27156
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.
Thedaylightstudio Fuel Cms 1.5.1
NA
CVE-2020-24950
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote malicious users to execute arbitrary code via the col parameter to function list_items.
Thedaylightstudio Fuel Cms 1.4.9
312
VMScore
CVE-2018-20136
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
Thedaylightstudio Fuel Cms 1.4.3
312
VMScore
CVE-2018-20137
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
Thedaylightstudio Fuel Cms 1.4.3
312
VMScore
CVE-2022-28599
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.
Thedaylightstudio Fuel Cms 1.5.1
383
VMScore
CVE-2020-28705
FUEL CMS 1.4.13 contains a cross-site request forgery (CSRF) vulnerability that can delete a page via a post ID to /pages/delete/3.
Thedaylightstudio Fuel Cms 1.4.13
NA
CVE-2021-36569
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote malicious users to run arbitrary code via post ID to /users/delete/2.
Thedaylightstudio Fuel Cms 1.4.13
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
NULL pointer dereference
CVE-2023-52689
CVE-2024-23803
client side
CVE-2023-52696
information disclosure
CVE-2024-35843
CVE-2024-27130
CVE-2023-52697
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »