İçeriğe atla
Noroxi

thedaylightstudio kayıtları

thedaylightstudio üreticisine ait 40 yayımlanmış kayıt.

Tüm kayıtlar

40 kayıt
  • FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90

    thedaylightstudio · fuel cms13 Ağu 2020

  • CVE-2018-16763
    64Bu hafta

    FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.

    KritikCVSS 9,8Kavram kanıtıEPSS %83

    thedaylightstudio · fuel cms9 Eyl 2018

  • CVE-2020-26167
    40Planlayın

    In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an adm

    KritikCVSS 9,8İstismar yokEPSS %3

    thedaylightstudio · fuel cms4 Kas 2020

  • CVE-2020-24791
    40Planlayın

    FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1.

    KritikCVSS 9,8İstismar yokEPSS %3

    thedaylightstudio · fuel cms10 Mar 2021

  • CVE-2020-26045
    40Planlayın

    FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/.

    KritikCVSS 9,8İstismar yokEPSS %2

    thedaylightstudio · fuel cms5 Oca 2021

  • CVE-2021-38727
    39İzleyin

    FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items

    KritikCVSS 9,8İstismar yokEPSS %2

    thedaylightstudio · fuel cms9 Eyl 2021

  • CVE-2020-22153
    39İzleyin

    File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload param

    KritikCVSS 9,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms3 Tem 2023

  • CVE-2020-22151
    39İzleyin

    Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests param

    KritikCVSS 9,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms3 Tem 2023

  • CVE-2018-16762
    39İzleyin

    FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.

    KritikCVSS 9,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms9 Eyl 2018

  • CVE-2026-30457
    39İzleyin

    An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

    KritikCVSS 9,8İstismar yokEPSS %1

    thedaylightstudio · dwoo26 Mar 2026

  • CVE-2026-30458
    36İzleyin

    An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

    KritikCVSS 9,1İstismar yokEPSS %0

    thedaylightstudio · fuel cms26 Mar 2026

  • CVE-2020-24950
    35İzleyin

    SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbi

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms11 Ağu 2023

  • CVE-2021-44117
    35İzleyin

    A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4

    YüksekCVSS 8,8Kavram kanıtıEPSS %1

    thedaylightstudio · fuel cms10 Haz 2022

  • CVE-2021-38723
    35İzleyin

    FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms9 Eyl 2021

  • CVE-2020-23722
    35İzleyin

    An issue was discovered in FUEL CMS 1.4.7.

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms10 Mar 2021

  • CVE-2026-30460
    35İzleyin

    Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms7 Nis 2026

  • CVE-2018-16416
    35İzleyin

    Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrat

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms3 Eyl 2018

  • CVE-2023-33557
    35İzleyin

    Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms9 Haz 2023

  • CVE-2021-36570
    35İzleyin

    Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms3 Şub 2023

  • CVE-2019-15229
    35İzleyin

    FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console.

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms19 Ağu 2019

  • CVE-2018-20188
    35İzleyin

    FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.

    YüksekCVSS 8,8İstismar yokEPSS %1

    thedaylightstudio · fuel cms17 Ara 2018

  • CVE-2021-36569
    35İzleyin

    Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.

    YüksekCVSS 8,8İstismar yokEPSS %0

    thedaylightstudio · fuel cms3 Şub 2023

  • CVE-2026-30461
    33İzleyin

    Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Ins

    YüksekCVSS 8,3İstismar yokEPSS %1

    thedaylightstudio · fuel cms15 Nis 2026

  • CVE-2021-38290
    32İzleyin

    A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/librar

    YüksekCVSS 8,1İstismar yokEPSS %1

    thedaylightstudio · fuel cms9 Ağu 2021

  • CVE-2026-30463
    30İzleyin

    Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.

    YüksekCVSS 7,7İstismar yokEPSS %0

    thedaylightstudio · fuel cms26 Mar 2026