Fuel Cms

Vendor:

First CVE: Sep 3, 2018 · Active for 7 years

40
Total CVEs
More Total CVEs than 98% of tracked products
4.4
Avg CVEs / Year
Higher CVE frequency than 88% of tracked products
7.7
Avg CVSS
Higher Avg CVSS than 65% of tracked products
2.5%
KEV Rate
Higher KEV Rate than 98% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Fuel Cms over time

Volume of CVEsAvg CVSS Base Score
First CVE
Sep 3, 2018
7 years ago
Most Recent CVE
Apr 16, 2026
103 days ago

CVE Severity & Scoring

Fuel Cms40 CVEs
All CVEs353,240 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network40 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low38 (95.0%)
High2 (5.0%)
Unknown0 (0.0%)
User Interaction
None20 (50.0%)
Unknown0 (0.0%)
Required20 (50.0%)
Privileges Required
Low15 (37.5%)
High2 (5.0%)
None23 (57.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (40 CVEs).

40 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
Aug 13, 20209.897YESYES
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
Sep 9, 20189.888NOYES
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
Mar 26, 20269.835NONO
An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.
Mar 26, 20269.132NONO
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
Apr 7, 20268.831NONO
FUEL CMS 1.4.11 allows SQL Injection via parameter 'name' in /fuel/permissions/create/. Exploiting this issue could allow an attacker to compromise the application, access or modif
Jan 5, 20219.831NONO
FUEL CMS 1.4.1 allows SQL Injection via the layout, published, or search_term parameter to pages/items.
Sep 9, 20189.831NONO
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function add_git_subm
Apr 15, 20268.330NONO
FUEL CMS 1.5.0 allows SQL Injection via parameter 'col' in /fuel/index.php/fuel/logs/items
Sep 9, 20219.830NONO
FUEL CMS 1.4.8 allows SQL injection via the 'fuel_replace_id' parameter in pages/replace/1. Exploiting this issue could allow an attacker to compromise the application, access or m
Mar 10, 20219.829NONO

Exploit Exposure

Signals from CVEs in this product scope (40 CVEs).

CISA KEV
1 CVE
2.5% of CVEs· 98th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
5.0% of CVEs· 97th percentile
ExploitDB
1 CVE
2.5% of CVEs· 85th percentile

Social Chatter

Signals from CVEs in this product scope (40 CVEs).

Media Mentions

Signals from CVEs in this product scope (40 CVEs).

Top CNAs Publishing CVEs For Fuel Cms

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.5.297.80.5%00
1.5.135.40.5%00
1.5.057.81.1%00
1.4.918.81.1%00
1.4.819.82.6%00
1.4.738.030.5%11
1.4.638.31.2%00
1.4.336.10.5%00
1.4.1337.30.6%00
1.4.1127.61.3%00
1.418.80.9%00