Interinfo
Interinfo Dreammaker: vulnerabilidades y CVE
Interinfo Dreammaker tiene 11 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses9
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-85541 | Media (4.8) | 0.28% | — | 4 sept 2026 | DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website. |
| CVE-2026-85540 | Alta (8.7) | 0.54% | — | 4 sept 2026 | DreamMaker developed by Interinfo has a SQL Injection vulnerability. Authenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents. |
| CVE-2026-10075 | Media (6.9) | 0.39% | — | 29 may 2026 | DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulnerability. |
| CVE-2026-10074 | Media (6.9) | 0.35% | — | 29 may 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files. |
| CVE-2026-10073 | Alta (8.7) | 0.35% | — | 29 may 2026 | DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files. |
| CVE-2026-10072 | Alta (8.6) | 0.46% | — | 29 may 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. |
| CVE-2026-10071 | Crítica (9.3) | 0.51% | — | 29 may 2026 | DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution on the server. |
| CVE-2026-24729 | Crítica (10) | 0.36% | — | 30 ene 2026 | An unrestricted upload of file with dangerous type vulnerability in the file upload function of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to execute arbitrary system commands via a… |
| CVE-2026-24728 | Crítica (9.3) | 0.53% | — | 30 ene 2026 | A missing authentication for critical function vulnerability in the /servlet/baServer3 endpoint of Interinfo DreamMaker versions before 2025/10/22 allows remote attackers to access exposed administrative functionality… |
| CVE-2024-11979 | Crítica (9.8) | 0.78% | — | 29 nov 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability and does not restrict the types of uploaded files. This allows unauthenticated remote attackers to upload arbitrary files to any directory, leading to… |
| CVE-2024-11978 | Alta (7.5) | 0.75% | — | 29 nov 2024 | DreamMaker from Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read arbitrary system files. |