Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thedaylightstudio vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2021-36570
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote malicious users to run arbitrary code via post ID to /permissions/delete/2---.
Thedaylightstudio Fuel Cms 1.4.13
9.8
CVSSv3
CVE-2020-22151
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote malicious user to execute arbitrary code via a crafted zip file to the assests parameter of the upload function.
Thedaylightstudio Fuel Cms 1.4.6
5.4
CVSSv3
CVE-2020-22152
Cross Site Scripting vulnerability in daylight studio FUEL- CMS v.1.4.6 allows a remote malicious user to execute arbitrary code via the page title, meta description and meta keywords of the pages function.
Thedaylightstudio Fuel Cms 1.4.6
9.8
CVSSv3
CVE-2020-22153
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote malicious user to execute arbitrary code via a crafted .php file to the upload parameter in the navigation function.
Thedaylightstudio Fuel Cms 1.4.6
9.8
CVSSv3
CVE-2020-17463
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Thedaylightstudio Fuel Cms 1.4.7
4.8
CVSSv3
CVE-2018-20137
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
Thedaylightstudio Fuel Cms 1.4.3
9.8
CVSSv3
CVE-2020-24791
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an malicious user to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database.
Thedaylightstudio Fuel Cms 1.4.8
8.8
CVSSv3
CVE-2020-24950
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote malicious users to execute arbitrary code via the col parameter to function list_items.
Thedaylightstudio Fuel Cms 1.4.9
8.8
CVSSv3
CVE-2018-16416
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote malicious users to change the administrator's password.
Thedaylightstudio Fuel Cms 1.4
4.8
CVSSv3
CVE-2018-20136
XSS exists in FUEL CMS 1.4.3 via the Header or Body in the Layout Variables during new-page creation, as demonstrated by the pages/edit/1?lang=english URI.
Thedaylightstudio Fuel Cms 1.4.3
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »