Dreamlevels maintains a small portfolio of web-based content and polling applications, including DreamPoll, Dream Pics Builder, and DreamNews Manager, where vulnerabilities cluster around web-layer input-handling flaws such as SQL injection and cross-site scripting. The recurring weakness classes reflect common risks in server-side web applications where user input flows into database queries and page rendering without sufficient sanitization. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Dreamlevels over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-4254HIGH SQL injection vulnerability in view_Results.php in DreamLevels DreamPoll 3.0 final allows remote attackers to execute arbitrary SQL commands via the id parameter. | Dec 15, 2005 | 7.5 | 29 | NO | YES |
CVE-2009-4745HIGH Multiple SQL injection vulnerabilities in index.php in Dreamlevels DreamPoll 3.1 allow remote attackers to execute arbitrary SQL commands via the (1) sortField, (2) sortDesc, or (3 | Mar 26, 2010 | 7.5 | 28 | NO | YES |
CVE-2008-3189HIGH SQL injection vulnerability in dreamnews-rss.php in DreamNews Manager allows remote attackers to execute arbitrary SQL commands via the id parameter. | Jul 16, 2008 | 7.5 | 28 | NO | YES |
CVE-2008-3119HIGH SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands via the page parameter. | Jul 10, 2008 | 7.5 | 28 | NO | YES |
CVE-2009-4746MEDIUM Cross-site scripting (XSS) vulnerability in index.php in Dreamlevels DreamPoll 3.1 allows remote attackers to inject arbitrary web script or HTML via the recordsPerPage parameter i | Mar 26, 2010 | 4.3 | 21 | NO | YES |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Dreamlevels.
Media articles that mention a CVE ID that affects a product developed by Dreamlevels — matched by CVE ID, not by vendor name.