CVE-2020-26046: Thedaylightstudio Fuel CMS

Medium severity, CVSS 5.4. EPSS: 0.7% chance of exploitation in the next 30 days.

FUEL CMS 1.4.11 has stored XSS in Blocks/Navigation/Site variables. This could lead to cookie stealing and other malicious actions. This vulnerability can be exploited with an authenticated account and also impact other visitors.

Affected products

Published 2021-01-05. Last modified 2026-06-17.