Fuel Cms
Vendor:
First CVE: Sep 3, 2018 · Active for 7 years
40
Total CVEs
More Total CVEs than 98% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 98% of tracked products
Trends Over Time
The number and severity of CVEs published that impact Fuel Cms over time
Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2018
7 years ago
Most Recent CVE
Apr 16, 2026
103 days ago
CVE Severity & Scoring
Fuel Cms40 CVEs
35%
38%
28%
All CVEs353,240 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (95.0%)
High2 (5.0%)
Unknown0 (0.0%)
User Interaction
None20 (50.0%)
Unknown0 (0.0%)
Required20 (50.0%)
Privileges Required
Low15 (37.5%)
High2 (5.0%)
None23 (57.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (40 CVEs).
40 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2020-17463CRITICAL FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items. | Aug 13, 2020 | 9.8 | 97 | YES | YES |
CVE-2018-16763CRITICAL FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution. | Sep 9, 2018 | 9.8 | 88 | NO | YES |
CVE-2026-30457CRITICAL An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code. | Mar 26, 2026 | 9.8 | 35 | NO | NO |
CVE-2026-30458CRITICAL An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack. | Mar 26, 2026 | 9.1 | 32 | NO | NO |
CVE-2026-30460HIGH Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module. | Apr 7, 2026 | 8.8 | 31 | NO | NO |
CVE-2020-26045CRITICAL FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modif | Jan 5, 2021 | 9.8 | 31 | NO | NO |
CVE-2018-16762CRITICAL FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items. | Sep 9, 2018 | 9.8 | 31 | NO | NO |
CVE-2026-30461HIGH Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_subm | Apr 15, 2026 | 8.3 | 30 | NO | NO |
CVE-2021-38727CRITICAL FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items | Sep 9, 2021 | 9.8 | 30 | NO | NO |
CVE-2020-24791CRITICAL FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or m | Mar 10, 2021 | 9.8 | 29 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (40 CVEs).
CISA KEV
1 CVE
2.5% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.0% of CVEs· 97th percentile
ExploitDB
1 CVE
2.5% of CVEs· 85th percentile
Social Chatter
Signals from CVEs in this product scope (40 CVEs).
Media Mentions
Signals from CVEs in this product scope (40 CVEs).
Top CNAs Publishing CVEs For Fuel Cms
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 1.5.2 | 9 | 7.8 | 0.5% | 0 | 0 |
| 1.5.1 | 3 | 5.4 | 0.5% | 0 | 0 |
| 1.5.0 | 5 | 7.8 | 1.1% | 0 | 0 |
| 1.4.9 | 1 | 8.8 | 1.1% | 0 | 0 |
| 1.4.8 | 1 | 9.8 | 2.6% | 0 | 0 |
| 1.4.7 | 3 | 8.0 | 30.5% | 1 | 1 |
| 1.4.6 | 3 | 8.3 | 1.2% | 0 | 0 |
| 1.4.3 | 3 | 6.1 | 0.5% | 0 | 0 |
| 1.4.13 | 3 | 7.3 | 0.6% | 0 | 0 |
| 1.4.11 | 2 | 7.6 | 1.3% | 0 | 0 |
| 1.4 | 1 | 8.8 | 0.9% | 0 | 0 |