CVE-2018-16763
CRITICAL 9.8EPSS 82.9%
FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.
- CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 82.94% chance of exploitation in the next 30 days, 100th percentile
- Nuclei
- critical · CWE-74
- Published
- 2018-09-09
- Updated
- 2024-08-05
Proof-of-concept exploits (50)
- http://packetstormsecurity.com/files/153696/fuelCMS-1.4.1-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/160080/Fuel-CMS-1.4-Remote-Code-Execution.html
- http://packetstormsecurity.com/files/164756/Fuel-CMS-1.4.1-Remote-Code-Execution.html
- https://0xd0ff9.wordpress.com/2019/07/19/from-code-evaluation-to-pre-auth-remote-code-exe…
- ArtemCyberLab/Project-Exploiting-a-Vulnerability-in-Fuel-CMS-CVE-2018-16763-0★ · 2025-04-13
- B7T3/CVE-2018-16763_FuelCMS-1.4.1_RCE0★ · 2025-09-09
- BrunoPincho/cve-2018-16763-rust0★ · 2022-01-27
- CovertOperation/Fuel-CMS-1.4.10★ · 2025-04-02
- Errahulaws/fuel-cms-1.4-RCA-exploit0★ · 2024-09-07
- N3rdyN3xus/CVE-2018-167632★ · 2025-06-05
- NyxByt3/CVE-2018-167632★ · 2025-06-05
- SlizBinksman/THM-Vulnerability_Capstone-CVE-2018-167630★ · 2021-11-22
- Sp3c73rSh4d0w/CVE-2018-167632★ · 2025-06-05
- VitoBonetti/CVE-2018-167630★ · 2023-07-16
- altsun/CVE-2018-16763-FuelCMS-1.4.1-RCE5★ · 2025-01-08
- andreidiaconescu18/FuelCMS-1.4.1-RCE-for-TryHackMe1★ · 2025-03-29
- antisecc/CVE-2018-167630★ · 2023-06-09
- apololifter/fuelcms-rce0★ · 2025-05-22
- c0d3cr4f73r/CVE-2018-167632★ · 2025-06-05
- crypticdante/CVE-2018-167632★ · 2025-06-05
- dinhbaouit/CVE-2018-167631★ · 2020-03-26
- dv-smith/Tryhackme-Vulnerability-Capstone0★ · 2025-07-17
- ecebotarosh/CVE-2018-16763-exploit2★ · 2020-09-03
- h3x0v3rl0rd/CVE-2018-167632★ · 2025-06-05
- h3xcr4ck3r/CVE-2018-167632★ · 2025-06-05
- hikarihacks/CVE-2018-16763-exploit2★ · 2020-09-03
- ice-wzl/Fuel-1.4.1-RCE-Updated14★ · 2024-03-13
- jtaubs1/Fuel-1.4.1-RCE-Updated14★ · 2024-03-13
- k4is3r13/Bash-Script-CVE-2018-167632★ · 2021-11-30
- k4u5h41/CVE-2018-167632★ · 2025-06-05
- kxisxr/Bash-Script-CVE-2018-167632★ · 2021-11-30
- n3m1dotsys/CVE-2018-16763-Exploit-Python34★ · 2021-10-18
- n3m1sys/CVE-2018-16763-Exploit-Python34★ · 2021-10-18
- n3ov4n1sh/CVE-2018-167632★ · 2025-06-05
- n3rdh4x0r/CVE-2018-167632★ · 2025-06-05
- noraj/fuelcms-rce7★ · 2025-09-18
- not1cyyy/CVE-2018-167632★ · 2023-04-10
- p0dalirius/CVE-2018-16763-FuelCMS-1.4.1-RCE26★ · 2025-01-31
- padsalatushal/CVE-2018-167636★ · 2021-11-13
- saccles/CVE-2018-16763-Proof-of-Concept0★ · 2025-02-22
- saccles/CVE_2018_16763_Proof_of_Concept0★ · 2025-02-22
- savior-only/javafx_tools128★ · 2022-08-05
- shoamshilo/Fuel-CMS-Remote-Code-Execution-1.4--RCE--3★ · 2021-03-07
- wizardy0ga/THM-Vulnerability_Capstone-CVE-2018-167630★ · 2021-11-22
- Cyberuser-hash/CVE-2018-16763
- ShadowR-Root/fuel-cms-cve-2018-16763-python3-port
- bad-c0de/CVE-2018-16763_FuelCMS-1.4.1_RCE
- estebanzarate/CVE-2018-16763-Fuel-CMS-1.4.1-Remote-Code-Execution-PoC
- gh0stuncle/CVE-2018-16763_fuel_cms_exploit
- kaxm23/exploit_cms_fuel
Nuclei templates (1)
ExploitDB entries (3)
- https://www.exploit-db.com/exploits/50477
- https://www.exploit-db.com/exploits/49487
- https://www.exploit-db.com/exploits/47138