thedaylightstudio kayıtları
thedaylightstudio üreticisine ait 40 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 1 · %2,5
- Silahlaştırılmış
- 1 · %2,5
- Pre-auth RCE
- 7
- Düzeltme kaydı olan
- %2,5
- Yayından KEV’e ortanca
- 484 gün
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')11
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')9
- CWE-352 Cross-Site Request Forgery (CSRF)8
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')2
- CWE-434 Unrestricted Upload of File with Dangerous Type2
- CWE-94 Improper Control of Generation of Code ('Code Injection')2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
40 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
96Hemen | CVE-2020-17463Silahlaştırılmış | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.thedaylightstudio · fuel cms · CWE-89 | Kritik9,8 | KEV | %89,7 | 13 Ağu 2020 |
64Bu hafta | CVE-2018-16763Kavram kanıtı | FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.thedaylightstudio · fuel cms · CWE-74 | Kritik9,8 | — | %82,9 | 9 Eyl 2018 |
40Planlayın | CVE-2020-26167İstismar yok | In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an admthedaylightstudio · fuel cms | Kritik9,8 | — | %3,4 | 4 Kas 2020 |
40Planlayın | CVE-2020-24791İstismar yok | FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1.thedaylightstudio · fuel cms · CWE-89 | Kritik9,8 | — | %2,6 | 10 Mar 2021 |
40Planlayın | CVE-2020-26045İstismar yok | FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/.thedaylightstudio · fuel cms · CWE-89 | Kritik9,8 | — | %1,9 | 5 Oca 2021 |
39İzleyin | CVE-2021-38727İstismar yok | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/itemsthedaylightstudio · fuel cms · CWE-89 | Kritik9,8 | — | %1,6 | 9 Eyl 2021 |
39İzleyin | CVE-2020-22153İstismar yok | File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload paramthedaylightstudio · fuel cms · CWE-434 | Kritik9,8 | — | %1,5 | 3 Tem 2023 |
39İzleyin | CVE-2020-22151İstismar yok | Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests paramthedaylightstudio · fuel cms · CWE-434 | Kritik9,8 | — | %1,5 | 3 Tem 2023 |
39İzleyin | CVE-2018-16762İstismar yok | FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.thedaylightstudio · fuel cms · CWE-89 | Kritik9,8 | — | %1,4 | 9 Eyl 2018 |
39İzleyin | CVE-2026-30457İstismar yok | An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.thedaylightstudio · dwoo · CWE-94 | Kritik9,8 | — | %0,8 | 26 Mar 2026 |
36İzleyin | CVE-2026-30458İstismar yok | An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.thedaylightstudio · fuel cms · CWE-620 | Kritik9,1 | — | %0,4 | 26 Mar 2026 |
35İzleyin | CVE-2020-24950İstismar yok | SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbithedaylightstudio · fuel cms · CWE-89 | Yüksek8,8 | — | %1,4 | 11 Ağu 2023 |
35İzleyin | CVE-2021-44117Kavram kanıtı | A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4thedaylightstudio · fuel cms · CWE-352 | Yüksek8,8 | — | %1,4 | 10 Haz 2022 |
35İzleyin | CVE-2021-38723İstismar yok | FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/itemsthedaylightstudio · fuel cms · CWE-89 | Yüksek8,8 | — | %1,0 | 9 Eyl 2021 |
35İzleyin | CVE-2020-23722İstismar yok | An issue was discovered in FUEL CMS 1.4.7.thedaylightstudio · fuel cms · CWE-639 | Yüksek8,8 | — | %1,0 | 10 Mar 2021 |
35İzleyin | CVE-2026-30460İstismar yok | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.thedaylightstudio · fuel cms · CWE-94 | Yüksek8,8 | — | %0,9 | 7 Nis 2026 |
35İzleyin | CVE-2018-16416İstismar yok | Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administratthedaylightstudio · fuel cms · CWE-352 | Yüksek8,8 | — | %0,9 | 3 Eyl 2018 |
35İzleyin | CVE-2023-33557İstismar yok | Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.thedaylightstudio · fuel cms · CWE-89 | Yüksek8,8 | — | %0,8 | 9 Haz 2023 |
35İzleyin | CVE-2021-36570İstismar yok | Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/deletethedaylightstudio · fuel cms · CWE-352 | Yüksek8,8 | — | %0,7 | 3 Şub 2023 |
35İzleyin | CVE-2019-15229İstismar yok | FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console.thedaylightstudio · fuel cms · CWE-352 | Yüksek8,8 | — | %0,7 | 19 Ağu 2019 |
35İzleyin | CVE-2018-20188İstismar yok | FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.thedaylightstudio · fuel cms · CWE-352 | Yüksek8,8 | — | %0,5 | 17 Ara 2018 |
35İzleyin | CVE-2021-36569İstismar yok | Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.thedaylightstudio · fuel cms · CWE-352 | Yüksek8,8 | — | %0,4 | 3 Şub 2023 |
33İzleyin | CVE-2026-30461İstismar yok | Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Insthedaylightstudio · fuel cms · CWE-77 | Yüksek8,3 | — | %0,7 | 15 Nis 2026 |
32İzleyin | CVE-2021-38290İstismar yok | A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/librarthedaylightstudio · fuel cms · CWE-74 | Yüksek8,1 | — | %1,3 | 9 Ağu 2021 |
30İzleyin | CVE-2026-30463İstismar yok | Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.thedaylightstudio · fuel cms · CWE-89 | Yüksek7,7 | — | %0,3 | 26 Mar 2026 |
- CVE-2020-1746396Hemen
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
KritikCVSS 9,8KEVSilahlaştırılmışEPSS %90thedaylightstudio · fuel cms13 Ağu 2020
- CVE-2018-1676364Bu hafta
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter.
KritikCVSS 9,8Kavram kanıtıEPSS %83thedaylightstudio · fuel cms9 Eyl 2018
- CVE-2020-2616740Planlayın
In FUEL CMS 11.4.12 and before, the page preview feature allows an anonymous user to take complete ownership of any account including an adm
KritikCVSS 9,8İstismar yokEPSS %3thedaylightstudio · fuel cms4 Kas 2020
- CVE-2020-2479140Planlayın
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1.
KritikCVSS 9,8İstismar yokEPSS %3thedaylightstudio · fuel cms10 Mar 2021
- CVE-2020-2604540Planlayın
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/.
KritikCVSS 9,8İstismar yokEPSS %2thedaylightstudio · fuel cms5 Oca 2021
- CVE-2021-3872739İzleyin
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
KritikCVSS 9,8İstismar yokEPSS %2thedaylightstudio · fuel cms9 Eyl 2021
- CVE-2020-2215339İzleyin
File Upload vulnerability in FUEL-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted .php file to the upload param
KritikCVSS 9,8İstismar yokEPSS %1thedaylightstudio · fuel cms3 Tem 2023
- CVE-2020-2215139İzleyin
Permissions vulnerability in Fuel-CMS v.1.4.6 allows a remote attacker to execute arbitrary code via a crafted zip file to the assests param
KritikCVSS 9,8İstismar yokEPSS %1thedaylightstudio · fuel cms3 Tem 2023
- CVE-2018-1676239İzleyin
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.
KritikCVSS 9,8İstismar yokEPSS %1thedaylightstudio · fuel cms9 Eyl 2018
- CVE-2026-3045739İzleyin
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
KritikCVSS 9,8İstismar yokEPSS %1thedaylightstudio · dwoo26 Mar 2026
- CVE-2026-3045836İzleyin
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
KritikCVSS 9,1İstismar yokEPSS %0thedaylightstudio · fuel cms26 Mar 2026
- CVE-2020-2495035İzleyin
SQL Injection vulnerability in file Base_module_model.php in Daylight Studio FUEL-CMS version 1.4.9, allows remote attackers to execute arbi
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms11 Ağu 2023
- CVE-2021-4411735İzleyin
A Cross Site Request Forgery (CSRF) vulnerability exists in TheDayLightStudio Fuel CMS 1.5.0 via a POST call to /fuel/sitevariables/delete/4
YüksekCVSS 8,8Kavram kanıtıEPSS %1thedaylightstudio · fuel cms10 Haz 2022
- CVE-2021-3872335İzleyin
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/pages/items
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms9 Eyl 2021
- CVE-2020-2372235İzleyin
An issue was discovered in FUEL CMS 1.4.7.
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms10 Mar 2021
- CVE-2026-3046035İzleyin
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms7 Nis 2026
- CVE-2018-1641635İzleyin
Cross-site request forgery (CSRF) vulnerability in my_profile/edit?inline= in FUEL CMS 1.4 allows remote attackers to change the administrat
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms3 Eyl 2018
- CVE-2023-3355735İzleyin
Fuel CMS v1.5.2 was discovered to contain a SQL injection vulnerability via the id parameter at /controllers/Blocks.php.
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms9 Haz 2023
- CVE-2021-3657035İzleyin
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /permissions/delete
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms3 Şub 2023
- CVE-2019-1522935İzleyin
FUEL CMS 1.4.4 has CSRF in the blocks/create/ Create Blocks section of the Admin console.
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms19 Ağu 2019
- CVE-2018-2018835İzleyin
FUEL CMS 1.4.3 has CSRF via users/create/ to add an administrator account.
YüksekCVSS 8,8İstismar yokEPSS %1thedaylightstudio · fuel cms17 Ara 2018
- CVE-2021-3656935İzleyin
Cross Site Request Forgery vulnerability in FUEL-CMS 1.4.13 allows remote attackers to run arbitrary code via post ID to /users/delete/2.
YüksekCVSS 8,8İstismar yokEPSS %0thedaylightstudio · fuel cms3 Şub 2023
- CVE-2026-3046133İzleyin
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Ins
YüksekCVSS 8,3İstismar yokEPSS %1thedaylightstudio · fuel cms15 Nis 2026
- CVE-2021-3829032İzleyin
A host header attack vulnerability exists in FUEL CMS 1.5.0 through fuel/modules/fuel/config/fuel_constants.php and fuel/modules/fuel/librar
YüksekCVSS 8,1İstismar yokEPSS %1thedaylightstudio · fuel cms9 Ağu 2021
- CVE-2026-3046330İzleyin
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
YüksekCVSS 7,7İstismar yokEPSS %0thedaylightstudio · fuel cms26 Mar 2026