Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1503 articles · 105592 vulns · 38/41 feeds (7d)
← Back to list
9.1
CVE-2026-30458EXPLOITED
n/a · n/a

CVE-2026-30458: An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt

Description

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

Affected Products

VendorProductVersions
n/an/an/a

References

  • https://github.com/daylightstudio/FUEL-CMS
  • http://daylight.com
  • http://fuelcms.com
  • https://pentest-tools.com/PTT-2025-025-Account-Takeover-via-Email-Array.pdf

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-30458 | Daylight Studio FuelCMS 1.5.2 Password Reset password recovery
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Published3/26/2026
Last enriched1d agov3
Trending Score60
Source articles1
Independent1
Info Completeness6/14
Missing: cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 1d ago
v3Tier C1d ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v2Tier C1d ago

Updated vendor and product information, changed severity to CRITICAL, and noted that the vulnerability is actively exploited.

vendorproductaffectedVersions
via VulDB
v11d ago

Initial creation