VendorsIteachyoudreamer_cmsany version
Vulnerabilities

Iteachyou Dreamer CMS any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2023-46886
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modification of the template file, allowing system sensitive files to be read.
Published 2023-11-29 · Modified
9.1EPSS 0.010
CVE-2024-3311
Dreamer CMS ThemesController.java ZipUtils.unZipFiles path traversal
Published 2024-04-04 · Analyzed
8.8EPSS 0.010
CVE-2024-3118
Dreamer CMS Attachment permission
Published 2024-03-31 · Analyzed
8.8EPSS 0.008
CVE-2023-2473
Dreamer CMS Password Hash Calculation UserController.java updatePwd algorithmic complexity
Published 2023-05-02 · Modified
7.5EPSS 0.009
CVE-2023-46887
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
Published 2023-11-29 · Modified
7.5EPSS 0.003
CVE-2023-0513
isoftforce Dreamer CMS cross site scripting
Published 2023-01-26 · Modified
5.4EPSS 0.007
CVE-2023-1746
Dreamer CMS File Upload cross site scripting
Published 2023-03-30 · Modified
5.4EPSS 0.006
CVE-2025-3977
iteachyou Dreamer CMS Attachment download improper authorization
Published 2025-04-27 · Analyzed
5.3EPSS 0.004
CVE-2023-4743
Dreamer CMS file access
Published 2023-09-03 · Modified
4.8EPSS 0.006