Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Thedaylightstudio

First CVE: Sep 3, 2018Active for: 8 yearsTotal CVEs: 40
70.5
VTI Score
TOP TARGET

Thedaylightstudio maintains a focused but security-sensitive portfolio centered on content management and templating systems, particularly Fuel CMS and Dwoo, that despite modest product breadth have accumulated a significant vulnerability history. Vulnerabilities affecting this vendor skew strongly toward critical-severity outcomes and recur persistently through application-layer input-handling weakness classes: cross-site scripting, SQL injection, code injection, and cross-site request forgery reflect the web-facing and template-processing attack surface inherent to these systems. The concentration of high-severity flaws in a relatively compact product line suggests that defenders deploying these systems should treat security updates as urgent and consider compensating controls for instances that cannot be quickly patched. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.

FAUCET AI Generated
40
Total CVEs
More Total CVEs than 98% of tracked vendors
2.2
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 90% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
2.5%
In CISA KEV
Higher KEV Rate than 99% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by Thedaylightstudio over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2018
7 years ago
Most Recent CVE
Apr 16, 2026
99 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2020-17463CRITICAL
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Aug 13, 20209.897YESYES
CVE-2018-16763CRITICAL
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
Sep 9, 20189.888NOYES
CVE-2026-30457CRITICAL
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
Mar 26, 20269.835NONO
CVE-2026-30458CRITICAL
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
Mar 26, 20269.132NONO
CVE-2026-30460HIGH
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
Apr 7, 20268.831NONO
CVE-2020-26045CRITICAL
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modif
Jan 5, 20219.831NONO
CVE-2018-16762CRITICAL
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.
Sep 9, 20189.831NONO
CVE-2026-30461HIGH
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_subm
Apr 15, 20268.330NONO
CVE-2021-38727CRITICAL
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
Sep 9, 20219.830NONO
CVE-2020-24791CRITICAL
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or m
Mar 10, 20219.829NONO
View all 40 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products40 CVEs
35%
38%
28%
Severity distribution among all CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (95.0%)
High2 (5.0%)
Unknown0 (0.0%)
User Interaction
None20 (50.0%)
Unknown0 (0.0%)
Required20 (50.0%)
Privileges Required
Low15 (37.5%)
High2 (5.0%)
None23 (57.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (40 CVEs).

CISA KEV
1 CVE
2.5% of CVEs· 99th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.0% of CVEs· 96th percentile
ExploitDB
1 CVE
2.5% of CVEs· 74th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Thedaylightstudio.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Thedaylightstudio — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Thedaylightstudio's Products

View all 1 CNAs →

Top CWEs