CVE-2018-16763: Thedaylightstudio Fuel CMS
Critical severity, CVSS 9.8. EPSS: 82.9% chance of exploitation in the next 30 days.
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
Affected products
- Thedaylightstudio Fuel CMS: up to and including 1.4.2
Published 2018-09-09. Last modified 2026-06-17.