CVE-2018-16763: Thedaylightstudio Fuel CMS

Critical severity, CVSS 9.8. EPSS: 82.9% chance of exploitation in the next 30 days.

FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

Affected products

Published 2018-09-09. Last modified 2026-06-17.