CVE-2025-64095
largeUnauthenticated File Upload and Overwrite in DNN (DotNetNuke) CMS
CVE-2025-64095 is an unauthenticated unrestricted file upload flaw (CWE-434) in the default HTML editor provider of DNN (formerly DotNetNuke), an open-source .NET web content management platform. Because the provider accepts uploads without authentication, any unauthenticated remote attacker can upload files and overwrite existing files, including images, with attacker-controlled content. This allows an attacker to deface a website by replacing its files and, combined with other issues, to inject cross-site-scripting (XSS) payloads; the CVSS 9.8 critical score reflects full network reachability with no privileges or user interaction required. All DNN deployments running any version prior to 10.1.1 are affected. Exploitation is not yet confirmed (not in CISA KEV, no public PoC known), but the EPSS score of 44.7% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days.
What to do: Upgrade DNN to version 10.1.1 or later as soon as possible. Until patched, restrict unauthenticated access to the HTML editor provider's upload endpoint (e.g., via authentication requirements or WAF/virtual-patching rules) and review existing uploaded images and site files for unexpected overwrites or injected XSS payloads.
| dnnsoftware (DNN Corporation) DNN (DotNetNuke) | all versions prior to 10.1.1 (fixed in 10.1.1) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, the default HTML editor provider allows unauthenticated file uploads and images can overwrite existing files. An unauthenticated user can upload and replace existing files allowing defacing a website and combined with other issue, injection XSS payloads. This vulnerability is fixed in 10.1.1.
- Vendors
- dnnsoftware
- Products
- dotnetnuke
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.