PT-2026-28398 · Fuel Cms · Fuel Cms

Published

2026-03-26

·

Updated

2026-03-29

·

CVE-2026-30457

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FuelCMS version 1.5.2
Description An issue exists in the /parser/dwoo component that allows attackers to execute arbitrary code through crafted PHP code. The affected component is susceptible to code execution when processing specially designed PHP code.
Recommendations Update FuelCMS to a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the /parser/dwoo component to minimize the risk of exploitation.

Exploit

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-30457

Affected Products

Fuel Cms