Home/Product/iteachyou dreamer cms
Product

iteachyou dreamer cms

40 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2025-3977
<= 4.1.3
A vulnerability was found in iteachyou Dreamer CMS up to 4.1.3. It has been declared as problematic. Affected by this vulnerabilit
4.3MEDIUM
CVE-2025-1548
all versions
A vulnerability was found in iteachyou Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown
3.5LOW
CVE-2025-1543
all versions
A vulnerability, which was classified as problematic, has been found in iteachyou Dreamer CMS 4.1.3. This issue affects some unkno
4.3MEDIUM
CVE-2024-3311
< 4.1.3.1
A vulnerability was found in Dreamer CMS up to 4.1.3.0. It has been declared as critical. Affected by this vulnerability is the fu
6.3MEDIUM
CVE-2024-3118
<= 4.1.3
A vulnerability, which was classified as critical, has been found in Dreamer CMS up to 4.1.3. This issue affects some unknown proc
6.3MEDIUM
CVE-2024-25811
all versions
An access control issue in Dreamer CMS v4.0.1 allows attackers to download backup files and leak sensitive information.
6.5MEDIUM
CVE-2024-2354
all versions
A vulnerability, which was classified as problematic, was found in Dreamer CMS 4.1.3. Affected is an unknown function of the file
4.3MEDIUM
CVE-2023-7091
all versions
A vulnerability was found in Dreamer CMS 4.1.3. It has been declared as problematic. This vulnerability affects unknown code of th
6.3MEDIUM
CVE-2023-50017
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/database/backup
8.8HIGH
CVE-2023-49484
all versions
Dreamer CMS v4.1.3 was discovered to contain a cross-site scripting (XSS) vulnerability in the article management department.
5.4MEDIUM
CVE-2023-48914
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/add.
8.8HIGH
CVE-2023-48913
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/delete.
8.8HIGH
CVE-2023-48912
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/archives/edit.
8.8HIGH
CVE-2023-46887
< 4.0.1
In Dreamer CMS before 4.0.1, the backend attachment management office has an Arbitrary File Download vulnerability.
7.5HIGH
CVE-2023-46886
< 4.0.1
Dreamer CMS before version 4.0.1 is vulnerable to Directory Traversal. Background template management allows arbitrary modificatio
9.1CRITICAL
CVE-2023-48017
all versions
Dreamer_cms 4.1.3 is vulnerable to Cross Site Request Forgery (CSRF) via Add permissions to CSRF in Permission Management.
8.8HIGH
CVE-2023-48021
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/update.
8.8HIGH
CVE-2023-48020
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) vulnerability via /admin/task/changeStatus.
8.8HIGH
CVE-2023-48063
all versions
An issue was discovered in dreamer_cms 4.1.3. There is a CSRF vulnerability that can delete a theme project via /admin/category/de
4.3MEDIUM
CVE-2023-48060
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/add
8.8HIGH
CVE-2023-48058
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/task/run
8.8HIGH
CVE-2023-45907
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/delete.
8.8HIGH
CVE-2023-45906
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/user/add.
8.8HIGH
CVE-2023-45905
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/variable/add.
8.8HIGH
CVE-2023-45904
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /variable/update.
8.8HIGH
CVE-2023-45903
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/label/delete.
8.8HIGH
CVE-2023-45902
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin/attachment/delete.
8.8HIGH
CVE-2023-45901
all versions
Dreamer CMS v4.1.3 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /admin\/category\/add.
8.8HIGH
CVE-2023-43857
all versions
Dreamer CMS v4.1.3 was discovered to contain a stored cross-site scripting (XSS) vulnerability via the component /admin/u/toIndex.
5.4MEDIUM
CVE-2023-43856
all versions
Dreamer CMS v4.1.3 was discovered to contain an arbitrary file read vulnerability via the component /admin/TemplateController.java
7.5HIGH
CVE-2023-43382
all versions
Directory Traversal vulnerability in itechyou dreamer CMS v.4.1.3 allows a remote attacker to execute arbitrary code via the theme
8.8HIGH
CVE-2023-42279
all versions
Dreamer CMS v4.1.3 was discovered to contain a SQL injection vulnerability via the model-form-management-field form.
9.8CRITICAL
CVE-2023-4743
<= 4.1.3
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been classified as problematic. Affected is an unknown function of th
3.1LOW
CVE-2023-2473
<= 4.1.3
A vulnerability was found in Dreamer CMS up to 4.1.3. It has been declared as problematic. This vulnerability affects the function
4.3MEDIUM
CVE-2023-29774
all versions
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS).
5.4MEDIUM
CVE-2023-1746
<= 3.5.0
A vulnerability, which was classified as problematic, was found in Dreamer CMS up to 3.5.0. Affected is an unknown function of the
3.5LOW
CVE-2023-27084
all versions
Permissions vulnerability found in isoftforce Dreamer CMS v.4.0.1 allows local attackers to obtain sensitive information via the A
5.3MEDIUM
CVE-2023-0513
<= 4.0.1
A vulnerability has been found in isoftforce Dreamer CMS up to 4.0.1 and classified as problematic. This vulnerability affects unk
3.5LOW
CVE-2022-42245
all versions
Dreamer CMS 4.0.01 is vulnerable to SQL Injection.
9.8CRITICAL
CVE-2021-43084
all versions
An SQL Injection vulnerability exists in Dreamer CMS 4.0.0 via the tableName parameter.
9.8CRITICAL
threatengine.sh