CVE-2026-30461: Command Injection
Published Apr 15, 2026
·Updated
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the /controllers/Installer.php and the function addgitsubmodule.
Affected Software
2 affected components
Daylight Studio FuelCMS=1.5.2
TheDayLightStudio Fuel CMS=1.5.2
Event History
Apr 15, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
DescriptionSeverityWeaknessAffected Software