Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thedaylightstudio fuel cms vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-44117
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.
Thedaylightstudio Fuel Cms 1.5.0
8.8
CVSSv3
CVE-2020-24950
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote malicious users to execute arbitrary code via the col parameter to function list_items.
Thedaylightstudio Fuel Cms 1.4.9
8.8
CVSSv3
CVE-2020-23722
An issue exists in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
Thedaylightstudio Fuel Cms 1.4.7
5.4
CVSSv3
CVE-2022-27156
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.
Thedaylightstudio Fuel Cms 1.5.1
5.4
CVSSv3
CVE-2020-26046
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.
Thedaylightstudio Fuel Cms 1.4.11
5.4
CVSSv3
CVE-2022-28599
A stored cross-site scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 that allows an authenticated user to upload a malicious .pdf file which acts as a stored XSS payload. If this stored XSS payload is triggered by an administrator it will trigger a XSS attack.
Thedaylightstudio Fuel Cms 1.5.1
5.4
CVSSv3
CVE-2020-23721
An issue exists in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.
Thedaylightstudio Fuel Cms 1.4.7
5.4
CVSSv3
CVE-2021-44607
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.
Thedaylightstudio Fuel Cms 1.5.1
9.8
CVSSv3
CVE-2020-22151
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote malicious user to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
Thedaylightstudio Fuel Cms 1.4.6
9.8
CVSSv3
CVE-2020-26045
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an malicious user to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Thedaylightstudio Fuel Cms 1.4.11
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2023-7073
CVE-2024-5496
CVE-2024-5495
XPath injection
bypass
CVE-2024-30043
CVE-2024-24919
denial of service
CVE-2024-35468
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »