Thedaylightstudio maintains a focused but security-sensitive portfolio centered on content management and templating systems, particularly Fuel CMS and Dwoo, that despite modest product breadth have accumulated a significant vulnerability history. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur persistently through application-layer input-handling weakness classes: cross-site scripting, SQL injection, code injection, and cross-site request forgery reflect the web-facing and template-processing attack surface inherent to these systems. The concentration of high-severity flaws in a relatively compact product line suggests that defenders deploying these systems should treat security updates as urgent and consider compensating controls for instances that cannot be quickly patched. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thedaylightstudio over time
Signals from CVEs in this vendor scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17463CRITICAL FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | Aug 13, 2020 | 9.8 | 97 | YES | YES |
CVE-2018-16763CRITICAL FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution. | Sep 9, 2018 | 9.8 | 88 | NO | YES |
CVE-2026-30457CRITICAL An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. | Mar 26, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-30458CRITICAL An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. | Mar 26, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-30460HIGH Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. | Apr 7, 2026 | 8.8 | 31 | NO | NO |
CVE-2020-26045CRITICAL FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modif | Jan 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-16762CRITICAL FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items. | Sep 9, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-30461HIGH Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_subm | Apr 15, 2026 | 8.3 | 30 | NO | NO |
CVE-2021-38727CRITICAL FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items | Sep 9, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-24791CRITICAL FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or m | Mar 10, 2021 | 9.8 | 29 | NO | NO |
Signals from CVEs in this vendor scope (40 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thedaylightstudio.
Media articles that mention a CVE ID that affects a product developed by Thedaylightstudio — matched by CVE ID, not by vendor name.