CVE-2026-30460

HIGH

FuelCMS 1.5.2 - Authenticated Remote Code Execution in Blocks Module

Title source: llm
STIX 2.1

Description

Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.

Scores

CVSS v3 8.8
EPSS 0.0092
EPSS Percentile 55.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
thedaylightstudio/fuel_cms 1.5.2
Published Apr 07, 2026
Tracked Since Apr 07, 2026