CVE-2023-42279
- EPSS 0.09%
- Veröffentlicht 21.09.2023 18:15:12
- Zuletzt bearbeitet 21.11.2024 08:22:23
Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
CVE-2023-4743
- EPSS 0.06%
- Veröffentlicht 03.09.2023 23:15:40
- Zuletzt bearbeitet 04.04.2025 15:16:10
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of the file /upload/ueditorConfig?action=config. The manipulation leads to files or directories accessible. It is possible to...
CVE-2023-2473
- EPSS 0.06%
- Veröffentlicht 02.05.2023 13:15:25
- Zuletzt bearbeitet 04.04.2025 15:16:10
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This vulnerability affects the function updatePwd of the file UserController.java of the component Password Hash Calculation. The manipulation leads to ineffic...
CVE-2023-29774
- EPSS 0.11%
- Veröffentlicht 18.04.2023 15:15:07
- Zuletzt bearbeitet 06.02.2025 16:15:35
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS).
CVE-2023-1746
- EPSS 0.09%
- Veröffentlicht 30.03.2023 23:15:06
- Zuletzt bearbeitet 04.04.2025 15:15:06
A vulnerability, which was classified as problematic, was found in Dreamer CMS up to 3.5.0. Affected is an unknown function of the component File Upload Handler. The manipulation leads to cross site scripting. It is possible to launch the attack remo...
CVE-2023-27084
- EPSS 0.04%
- Veröffentlicht 16.03.2023 02:15:08
- Zuletzt bearbeitet 04.04.2025 15:15:06
Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the AttachmentController parameter.
CVE-2023-0513
- EPSS 0.25%
- Veröffentlicht 26.01.2023 21:18:10
- Zuletzt bearbeitet 04.04.2025 15:16:10
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unknown code. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been di...
CVE-2021-43084
- EPSS 0.25%
- Veröffentlicht 24.03.2022 18:15:07
- Zuletzt bearbeitet 04.04.2025 15:15:06
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.