CVE-2020-26046: Thedaylightstudio Fuel CMS
Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.
FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.
Affected products
- Thedaylightstudio Fuel CMS: version 1.4.11 only
Published 2021-01-05. Last modified 2026-06-17.