Show filters
13 Total Results
Displaying 11-13 of 13
Sort by:
Attacker Value
Unknown

CVE-2023-43382

Disclosure Date: September 25, 2023 (last updated October 08, 2023)
Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the themePath in the uploaded template function.
Attacker Value
Unknown

CVE-2023-42279

Disclosure Date: September 21, 2023 (last updated March 08, 2024)
Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
Attacker Value
Unknown

CVE-2023-29774

Disclosure Date: April 18, 2023 (last updated October 08, 2023)
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS).