Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 23 Apr 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Thedaylightstudio
Thedaylightstudio fuel Cms |
|
| CPEs | cpe:2.3:a:thedaylightstudio:fuel_cms:1.5.2:*:*:*:*:*:*:* | |
| Vendors & Products |
Thedaylightstudio
Thedaylightstudio fuel Cms |
Fri, 17 Apr 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Retrieval of Password Reset Tokens via Forged Email Links in FuelCMS |
Thu, 16 Apr 2026 19:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Daylightstudio
Daylightstudio fuel Cms |
|
| Vendors & Products |
Daylightstudio
Daylightstudio fuel Cms |
Thu, 16 Apr 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-640 | |
| Metrics |
cvssV3_1
|
Thu, 16 Apr 2026 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the Forgot Password feature of Daylight Studio FuelCMS v1.5.2 allows unauthenticated attackers to obtain the password reset token of a victim user via a crafted link placed in a valid e-mail message. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-04-16T15:16:57.348Z
Reserved: 2026-03-04T00:00:00.000Z
Link: CVE-2026-30459
Updated: 2026-04-16T15:14:19.283Z
Status : Analyzed
Published: 2026-04-16T15:17:17.370
Modified: 2026-04-23T15:15:23.493
Link: CVE-2026-30459
No data.
OpenCVE Enrichment
Updated: 2026-04-17T06:30:11Z