thedaylightstudio records
40 published records for vendor thedaylightstudio.
Researcher profile
- Entered KEV
- 1 · 2.5%
- Weaponized
- 1 · 2.5%
- Pre-auth RCE
- 7
- With a fix record
- 2.5%
- Median publish → KEV
- 484 days
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
The weakness classes this vendor ships most often: where to look.
CWEAll records
40 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
96Now | CVE-2020-17463Weaponized | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.thedaylightstudio · fuel cms · CWE-89 | Critical9.8 | KEV | 89.7% | Aug 13, 2020 |
64This week | CVE-2018-16763Proof of concept | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.thedaylightstudio · fuel cms · CWE-74 | Critical9.8 | — | 82.9% | Sep 9, 2018 |
40Plan | CVE-2020-26167No exploit | In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an admthedaylightstudio · fuel cms | Critical9.8 | — | 3.4% | Nov 4, 2020 |
40Plan | CVE-2020-24791No exploit | FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1.thedaylightstudio · fuel cms · CWE-89 | Critical9.8 | — | 2.6% | Mar 10, 2021 |
40Plan | CVE-2020-26045No exploit | FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/.thedaylightstudio · fuel cms · CWE-89 | Critical9.8 | — | 1.9% | Jan 5, 2021 |
39Monitor | CVE-2021-38727No exploit | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/itemsthedaylightstudio · fuel cms · CWE-89 | Critical9.8 | — | 1.6% | Sep 9, 2021 |
39Monitor | CVE-2020-22153No exploit | File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload paramthedaylightstudio · fuel cms · CWE-434 | Critical9.8 | — | 1.5% | Jul 3, 2023 |
39Monitor | CVE-2020-22151No exploit | Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests paramthedaylightstudio · fuel cms · CWE-434 | Critical9.8 | — | 1.5% | Jul 3, 2023 |
39Monitor | CVE-2018-16762No exploit | FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.thedaylightstudio · fuel cms · CWE-89 | Critical9.8 | — | 1.4% | Sep 9, 2018 |
39Monitor | CVE-2026-30457No exploit | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.thedaylightstudio · dwoo · CWE-94 | Critical9.8 | — | 0.8% | Mar 26, 2026 |
36Monitor | CVE-2026-30458No exploit | An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.thedaylightstudio · fuel cms · CWE-620 | Critical9.1 | — | 0.4% | Mar 26, 2026 |
35Monitor | CVE-2020-24950No exploit | SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbithedaylightstudio · fuel cms · CWE-89 | High8.8 | — | 1.4% | Aug 11, 2023 |
35Monitor | CVE-2021-44117Proof of concept | A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4thedaylightstudio · fuel cms · CWE-352 | High8.8 | — | 1.4% | Jun 10, 2022 |
35Monitor | CVE-2021-38723No exploit | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/itemsthedaylightstudio · fuel cms · CWE-89 | High8.8 | — | 1.0% | Sep 9, 2021 |
35Monitor | CVE-2020-23722No exploit | An issue was discovered in FUEL CMS 1.4.7.thedaylightstudio · fuel cms · CWE-639 | High8.8 | — | 1.0% | Mar 10, 2021 |
35Monitor | CVE-2026-30460No exploit | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.thedaylightstudio · fuel cms · CWE-94 | High8.8 | — | 0.9% | Apr 7, 2026 |
35Monitor | CVE-2018-16416No exploit | Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administratthedaylightstudio · fuel cms · CWE-352 | High8.8 | — | 0.9% | Sep 3, 2018 |
35Monitor | CVE-2023-33557No exploit | Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.thedaylightstudio · fuel cms · CWE-89 | High8.8 | — | 0.8% | Jun 9, 2023 |
35Monitor | CVE-2021-36570No exploit | Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/deletethedaylightstudio · fuel cms · CWE-352 | High8.8 | — | 0.7% | Feb 3, 2023 |
35Monitor | CVE-2019-15229No exploit | FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console.thedaylightstudio · fuel cms · CWE-352 | High8.8 | — | 0.7% | Aug 19, 2019 |
35Monitor | CVE-2018-20188No exploit | FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.thedaylightstudio · fuel cms · CWE-352 | High8.8 | — | 0.5% | Dec 17, 2018 |
35Monitor | CVE-2021-36569No exploit | Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.thedaylightstudio · fuel cms · CWE-352 | High8.8 | — | 0.4% | Feb 3, 2023 |
33Monitor | CVE-2026-30461No exploit | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Insthedaylightstudio · fuel cms · CWE-77 | High8.3 | — | 0.7% | Apr 15, 2026 |
32Monitor | CVE-2021-38290No exploit | A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/librarthedaylightstudio · fuel cms · CWE-74 | High8.1 | — | 1.3% | Aug 9, 2021 |
30Monitor | CVE-2026-30463No exploit | Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.thedaylightstudio · fuel cms · CWE-89 | High7.7 | — | 0.3% | Mar 26, 2026 |
- CVE-2020-1746396Now
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
CriticalCVSS 9.8KEVWeaponizedEPSS 90%thedaylightstudio · fuel cmsAug 13, 2020
- CVE-2018-1676364This week
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.
CriticalCVSS 9.8Proof of conceptEPSS 83%thedaylightstudio · fuel cmsSep 9, 2018
- CVE-2020-2616740Plan
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an adm
CriticalCVSS 9.8No exploitEPSS 3%thedaylightstudio · fuel cmsNov 4, 2020
- CVE-2020-2479140Plan
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1.
CriticalCVSS 9.8No exploitEPSS 3%thedaylightstudio · fuel cmsMar 10, 2021
- CVE-2020-2604540Plan
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/.
CriticalCVSS 9.8No exploitEPSS 2%thedaylightstudio · fuel cmsJan 5, 2021
- CVE-2021-3872739Monitor
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
CriticalCVSS 9.8No exploitEPSS 2%thedaylightstudio · fuel cmsSep 9, 2021
- CVE-2020-2215339Monitor
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload param
CriticalCVSS 9.8No exploitEPSS 1%thedaylightstudio · fuel cmsJul 3, 2023
- CVE-2020-2215139Monitor
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests param
CriticalCVSS 9.8No exploitEPSS 1%thedaylightstudio · fuel cmsJul 3, 2023
- CVE-2018-1676239Monitor
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.
CriticalCVSS 9.8No exploitEPSS 1%thedaylightstudio · fuel cmsSep 9, 2018
- CVE-2026-3045739Monitor
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
CriticalCVSS 9.8No exploitEPSS 1%thedaylightstudio · dwooMar 26, 2026
- CVE-2026-3045836Monitor
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
CriticalCVSS 9.1No exploitEPSS 0%thedaylightstudio · fuel cmsMar 26, 2026
- CVE-2020-2495035Monitor
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbi
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsAug 11, 2023
- CVE-2021-4411735Monitor
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4
HighCVSS 8.8Proof of conceptEPSS 1%thedaylightstudio · fuel cmsJun 10, 2022
- CVE-2021-3872335Monitor
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsSep 9, 2021
- CVE-2020-2372235Monitor
An issue was discovered in FUEL CMS 1.4.7.
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsMar 10, 2021
- CVE-2026-3046035Monitor
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsApr 7, 2026
- CVE-2018-1641635Monitor
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrat
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsSep 3, 2018
- CVE-2023-3355735Monitor
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsJun 9, 2023
- CVE-2021-3657035Monitor
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsFeb 3, 2023
- CVE-2019-1522935Monitor
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console.
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsAug 19, 2019
- CVE-2018-2018835Monitor
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
HighCVSS 8.8No exploitEPSS 1%thedaylightstudio · fuel cmsDec 17, 2018
- CVE-2021-3656935Monitor
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
HighCVSS 8.8No exploitEPSS 0%thedaylightstudio · fuel cmsFeb 3, 2023
- CVE-2026-3046133Monitor
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Ins
HighCVSS 8.3No exploitEPSS 1%thedaylightstudio · fuel cmsApr 15, 2026
- CVE-2021-3829032Monitor
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/librar
HighCVSS 8.1No exploitEPSS 1%thedaylightstudio · fuel cmsAug 9, 2021
- CVE-2026-3046330Monitor
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
HighCVSS 7.7No exploitEPSS 0%thedaylightstudio · fuel cmsMar 26, 2026