🔐 CVE Alert

CVE-2026-85541

MEDIUM 5.4

Interinfo|DreamMaker - Reflected Cross-site Scripting

CVSS Score
5.4
EPSS Score
0.0%
EPSS Percentile
0th

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.

CWE CWE-79
Vendor interinfo
Product dreammaker
Published Sep 4, 2026
Last Updated Sep 4, 2026
Stay Ahead of the Next One

Get instant alerts for interinfo dreammaker

Be the first to know when new medium vulnerabilities affecting interinfo dreammaker are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
Low
Availability
None

Affected Versions

Interinfo / DreamMaker
all

References

NVD ↗ CVE.org ↗ EPSS Data ↗
twcert.org.tw: https://www.twcert.org.tw/tw/cp-132-11183-06a5e-1.html twcert.org.tw: https://www.twcert.org.tw/en/cp-139-11184-9ad14-2.html