CVE-2018-20137: Thedaylightstudio Fuel CMS

Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.

XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.

Affected products

Published 2018-12-13. Last modified 2026-06-17.