CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-30457

Critical · CVSS 9.8

Daylight Studio FuelCMS — PHP Code Injection / Arbitrary Code Execution (CWE-94)

CVSS
9.8
nvd
EPSS
0.71%
49th pct
KEV
No
Class
other
CWE-94

Description

An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.

Search profile — drives PoC discovery

Symbols parser/dwoofuel/modules/fuel/libraries/parser/dwoodwoo escapePTT-2025-026
Keywords CVE-2026-30457FuelCMSFuelCMS 1.5.2Dwoodwoo parserPHP code executioncode injectionRCEPTT-2025-026daylightstudio FUEL-CMS
Versions: v1.5.2

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-06T06:30:39.000Z