Home

Description

Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-privileged authenticated user to upload a crafted SVG file containing malicious code.

PUBLISHED Reserved 2026-04-06 | Published 2026-04-28 | Updated 2026-04-28 | Assigner mitre

References

github.com/...ve-research/blob/main/CVE-2026-38948/README.md exploit

github.com/daylightstudio/FUEL-CMS

www.youtube.com/watch?v=lLCF0xbjecQ

github.com/...ve-research/blob/main/CVE-2026-38948/README.md

cve.org (CVE-2026-38948)

nvd.nist.gov (CVE-2026-38948)

Download JSON