Search Results (3 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-30463 2 Daylightstudio, Thedaylightstudio 2 Fuel Cms, Fuel Cms 2026-03-30 7.7 High
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
CVE-2026-30458 2 Daylightstudio, Thedaylightstudio 2 Fuel Cms, Fuel Cms 2026-03-30 9.1 Critical
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
CVE-2026-30457 2 Daylightstudio, Thedaylightstudio 3 Fuel Cms, Dwoo, Fuel Cms 2026-03-30 9.8 Critical
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.