CVE-2026-30457

An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:thedaylightstudio:dwoo:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:thedaylightstudio:fuel_cms:1.5.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-03-26 19:16

Updated : 2026-07-05 17:17


NVD link : CVE-2026-30457

Mitre link : CVE-2026-30457

CVE.ORG link : CVE-2026-30457


JSON object : View

Products Affected

thedaylightstudio

  • dwoo
  • fuel_cms
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')