SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85541

MEDIUM · CVSS 5.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-04 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

DreamMaker, developed by Interinfo, contains a reflected cross-site scripting vulnerability that allows authenticated remote attackers to execute arbitrary JavaScript in users' browsers through malicious websites. This could lead to session hijacking, data theft, or other malicious actions. Organizations using DreamMaker should prioritize addressing this vulnerability to protect their users from potential exploitation.

CVE
CVE-2026-85541
Severity
MEDIUM
CVSS
5.4
EPSS
0.26%
Java

Original NVD Description

DreamMaker developed by Interinfo has a Reflected Cross-site Scripting vulnerability. Authenticated remote attackers can execute arbitrary JavaScript codes in user's browser via a malicious website.