Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
thedaylightstudio vulnerabilities and exploits
(subscribe to this query)
8.8
CVSSv3
CVE-2018-20188
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
Thedaylightstudio Fuel Cms 1.4.3
8.8
CVSSv3
CVE-2023-33557
Fuel CMS v1.5.2 exists to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
Thedaylightstudio Fuel Cms 1.5.2
5.4
CVSSv3
CVE-2021-44607
A Cross Site Scripting (XSS) vulnerability exists in FUEL-CMS 1.5.1 in the Assets page via an SVG file.
Thedaylightstudio Fuel Cms 1.5.1
5.4
CVSSv3
CVE-2022-27156
Daylight Studio Fuel CMS 1.5.1 is vulnerable to HTML Injection.
Thedaylightstudio Fuel Cms 1.5.1
8.8
CVSSv3
CVE-2021-44117
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4.
Thedaylightstudio Fuel Cms 1.5.0
5.4
CVSSv3
CVE-2020-26046
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.
Thedaylightstudio Fuel Cms 1.4.11
5.4
CVSSv3
CVE-2020-23721
An issue exists in FUEL CMS V1.4.7. An attacker can use a XSS payload and bypass a filter via /fuelCM/fuel/pages/edit/1?lang=english.
Thedaylightstudio Fuel Cms 1.4.7
8.8
CVSSv3
CVE-2020-23722
An issue exists in FUEL CMS 1.4.7. There is a escalation of privilege vulnerability to obtain super admin privilege via the "id" and "fuel_id" parameters.
Thedaylightstudio Fuel Cms 1.4.7
6.5
CVSSv3
CVE-2021-38721
FUEL CMS 1.5.0 login.php contains a cross-site request forgery (CSRF) vulnerability
Thedaylightstudio Fuel Cms 1.5.0
8.8
CVSSv3
CVE-2021-38723
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
Thedaylightstudio Fuel Cms 1.5.0
CVSSv3
CVSSv2
CVSSv3
VMScore
Recommendations:
SSTI
CVE-2024-35863
CVE-2024-35910
man-in-the-middle
CVE-2024-35912
CVE-2024-25742
LFI
CVE-2024-32002
CVE-2024-22120
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started
« PREV
1
2
3
4
NEXT »