CVEs affecting projects tracked on Release Alert, from NVD & OSV.
Dreamer CMS 3.0.1 is vulnerable to stored Cross Site Scripting (XSS).