VendorsIteachyoudreamer_cmsall versions
Vulnerabilities

Iteachyou Dreamer CMS

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

39CVEs
CVE-2021-43084
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
Published 2022-03-24 · Modified
9.8EPSS 0.010
CVE-2023-42279
Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
Published 2023-09-21 · Modified
9.8EPSS 0.008
CVE-2023-46886
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
Published 2023-11-29 · Modified
9.1EPSS 0.010
CVE-2023-43382
Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the themePath in the uploaded template function.
Published 2023-09-25 · Modified
8.8EPSS 0.015
CVE-2024-3311
Dreamer CMS ThemesController.java ZipUtils.unZipFiles path traversal
Published 2024-04-04 · Analyzed
8.8EPSS 0.010
CVE-2023-7091
Dreamer CMS uploadFile unrestricted upload
Published 2023-12-24 · Modified
8.8EPSS 0.009
CVE-2024-3118
Dreamer CMS Attachment permission
Published 2024-03-31 · Analyzed
8.8EPSS 0.008
CVE-2023-48060
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
Published 2023-11-13 · Modified
8.8EPSS 0.004
CVE-2023-48058
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
Published 2023-11-13 · Modified
8.8EPSS 0.004
CVE-2023-50017
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup
Published 2023-12-14 · Modified
8.8EPSS 0.004
CVE-2023-48912
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/edit.
Published 2023-11-30 · Modified
8.8EPSS 0.004
CVE-2023-48913
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/delete.
Published 2023-11-30 · Modified
8.8EPSS 0.004
CVE-2023-48914
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/add.
Published 2023-11-30 · Modified
8.8EPSS 0.004
CVE-2023-48021
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update.
Published 2023-11-14 · Modified
8.8EPSS 0.004
CVE-2023-48020
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeStatus.
Published 2023-11-14 · Modified
8.8EPSS 0.004
CVE-2023-48017
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
Published 2023-11-18 · Modified
8.8EPSS 0.004
CVE-2023-45901
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-45902
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-45903
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-45904
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-45905
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-45906
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-45907
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
Published 2023-10-17 · Modified
8.8EPSS 0.003
CVE-2023-2473
Dreamer CMS Password Hash Calculation UserController.java updatePwd algorithmic complexity
Published 2023-05-02 · Modified
7.5EPSS 0.009
CVE-2023-43856
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java.
Published 2023-09-26 · Modified
7.5EPSS 0.008
CVE-2023-46887
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Published 2023-11-29 · Modified
7.5EPSS 0.003
CVE-2024-25811
An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
Published 2024-02-29 · Analyzed
6.5EPSS 0.006
CVE-2024-2354
Dreamer CMS toEdit cross-site request forgery
Published 2024-03-10 · Analyzed
6.5EPSS 0.003
CVE-2023-0513
isoftforce Dreamer CMS cross site scripting
Published 2023-01-26 · Modified
5.4EPSS 0.007
CVE-2023-1746
Dreamer CMS File Upload cross site scripting
Published 2023-03-30 · Modified
5.4EPSS 0.006
CVE-2023-49484
Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.
Published 2023-12-08 · Modified
5.4EPSS 0.004
CVE-2023-43857
Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/u/toIndex.
Published 2023-09-26 · Modified
5.4EPSS 0.004
CVE-2023-29774
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS).
Published 2023-04-18 · Modified
5.4EPSS 0.003
CVE-2025-1543
iteachyou Dreamer CMS ueditor-1.4.3.3 path traversal
Published 2025-02-21 · Analyzed
5.3EPSS 0.008
CVE-2025-3977
iteachyou Dreamer CMS Attachment download improper authorization
Published 2025-04-27 · Analyzed
5.3EPSS 0.004
CVE-2023-27084
Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController parameter.
Published 2023-03-16 · Modified
5.3EPSS 0.002
CVE-2025-1548
iteachyou Dreamer CMS edit cross site scripting
Published 2025-02-21 · Analyzed
5.1EPSS 0.003
CVE-2023-4743
Dreamer CMS file access
Published 2023-09-03 · Modified
4.8EPSS 0.006
CVE-2023-48063
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/delete.
Published 2023-11-13 · Modified
4.3EPSS 0.002