Products: 1
Vulnerabilities: 8
Known Exploited: 0
2
Critical Level Threats
4
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-38948
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.
Last Modified: Apr 29, 2026
Published: Apr 28, 2026
CVE-2026-30462
Directory Traversal in Daylight Studio FuelCMS Blocks Module 1.5.2
Last Modified: Apr 29, 2026
Published: Apr 27, 2026
CVE-2026-30459
Unauthenticated Retrieval of Password Reset Tokens via Forged Email Links in FuelCMS
Last Modified: Apr 23, 2026
Published: Apr 16, 2026
CVE-2026-30461
Authenticated Remote Code Execution in FuelCMS via Git Submodule Function
Last Modified: Apr 20, 2026
Published: Apr 15, 2026
CVE-2026-30460
Authenticated Remote Code Execution via Blocks Module in FuelCMS 1.5.2
Last Modified: Apr 13, 2026
Published: Apr 07, 2026
Items Per Page
