Review reviewCritical
CVE-2026-30457
dwoo, fuel cms
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
- CVSS
- 9.8
- EPSS
- 0.63% 46.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.27