CVE-2018-20137: Thedaylightstudio Fuel CMS
Medium severity, CVSS 4.8. EPSS: 0.6% chance of exploitation in the next 30 days.
XSS exists in FUEL CMS 1.4.3 via the Page title, Meta description, or Meta keywords during page data management, as demonstrated by the pages/edit/1?lang=english URI.
Affected products
- Thedaylightstudio Fuel CMS: version 1.4.3 only
Published 2018-12-13. Last modified 2026-06-17.