Zero Day Monitor
DashboardVulnerabilitiesTrendingZero-DaysNews
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
1489 articles · 105579 vulns · 38/41 feeds (7d)
← Back to list
9.1
CVE-2026-30458EXPLOITED
n/a · n/a

CVE-2026-30458: An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitt

Description

An issue in Daylight Studio FuelCMS v1.5.2 allows attackers to exfiltrate users' password reset tokens via a mail splitting attack.

Affected Products

VendorProductVersions
n/an/an/a

References

  • https://github.com/daylightstudio/FUEL-CMS
  • http://daylight.com
  • http://fuelcms.com
  • https://pentest-tools.com/PTT-2025-025-Account-Takeover-via-Email-Array.pdf

Related News (1 articles)

Tier C
VulDB1d ago
CVE-2026-30458 | Daylight Studio FuelCMS 1.5.2 Password Reset password recovery
→ No new info (linked only)
CVSS 3.19.1 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
CISA KEV❌ No
Actively exploited✅ Yes
Published3/26/2026
Last enriched21h agov3
Trending Score61
Source articles1
Independent1
Info Completeness6/14
Missing: cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Version History

v3
Last enriched 21h ago
v3Tier C21h ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v2Tier C1d ago

Updated vendor and product information, changed severity to CRITICAL, and noted that the vulnerability is actively exploited.

vendorproductaffectedVersions
via VulDB
v11d ago

Initial creation