Review reviewHigh
CVE-2026-30463
fuel cms
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
- CVSS
- 7.7
- EPSS
- 0.31% 23.2% percentile
- CISA KEV
- Not listed
- Published
- 2026.03.27
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
The CVSS severity warrants an early asset and exposure review.
Daylight Studio FuelCMS v1.5.2 was discovered to contain a SQL injection vulnerability via the /controllers/Login.php component.
Confirm exposure before applying a vendor-supported change.
Confirm that fuel cms and an affected version are present.
Combine exploitation signals with asset exposure and business criticality.
Follow the vendor advisory or supported update path and preserve rollback options.
Recheck the version, service health, access paths, and relevant logs.