Vulnerabilities
49 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-40321 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. NVD description · AI analysis pending | 8.0 group max | 8% |
| — | ||
| CVE-2020-37103 | DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through j DotNetNuke 9.5 contains a persistent cross-site scripting vulnerability that allows normal users to upload malicious XML files with executable scripts through journal tools. Attackers can upload XML files with XHTML namespace scripts to execute arbitrary JavaScript in users' browsers, potentially bypassing CSRF protections and performing more damaging attacks. NVD description · AI analysis pending | 5.1 | <1% | PoC |
| — | |
| CVE-2026-24837 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a module friendly name could include scripts that will run during some module operations in the Persona Bar. Versions 9.13.10 and 10.2.0 contain a fix for the issue. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2025-64095 | Unauthenticated File Upload and Overwrite in DNN (DotNetNuke) CMS CVE-2025-64095 is an unauthenticated unrestricted file upload flaw (CWE-434) in the default HTML editor provider of DNN (formerly DotNetNuke), an open-source .NET web content management platform. Because the provider accepts uploads without authentication, any unauthenticated remote attacker can upload files and overwrite existing files, including images, with attacker-controlled content. This allows an attacker to deface a website by replacing its files and, combined with other issues, to inject cross-site-scripting (XSS) payloads; the CVSS 9.8 critical score reflects full network reachability with no privileges or user interaction required. All DNN deployments running any version prior to 10.1.1 are affected. Exploitation is not yet confirmed (not in CISA KEV, no public PoC known), but the EPSS score of 44.7% (99th percentile) indicates an elevated likelihood of exploitation within the next 30 days. Do: Upgrade DNN to version 10.1.1 or later as soon as possible. Until patched, restrict unauthenticated access to the HTML editor provider's upload endpoint (e.g., via authentication requirements or WAF/virtual-patching rules) and review existing uploaded images and site files for unexpected overwrites or injected XSS payloads. | 9.8 group max | 45% |
| largetens of thousands of internet-facing DNN sites (order 10k-100k) | ||
| CVE-2025-59545 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). This issue has been patched in version 10.1.0. NVD description · AI analysis pending | 9.0 group max | <1% |
| — | ||
| CVE-2025-59535 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. This issue has been patched in version 10.1.0. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2025-52488 | Unauthenticated NTLM Hash Leak to Attacker-Controlled SMB Server in DNN Platform CVE-2025-52488 is an information-disclosure flaw in DNN Platform (formerly DotNetNuke), an open-source .NET-based web CMS, that allows a specially crafted series of malicious interactions to expose NTLM authentication hashes. An unauthenticated network attacker can trigger the DNN web server to authenticate to a third-party (attacker-controlled) SMB server, capturing the NTLM hashes of the account running the application. Those hashes can be cracked offline or relayed to other services, potentially yielding valid credentials for the web server's service account and broader movement in Windows/Active Directory environments — consistent with the scope-changed, high-confidentiality CVSS 3.1 score of 8.6. All DNN Platform deployments from version 6.0.0 up to but not including 10.0.1 are affected, especially Windows-hosted servers whose application pool identity is a domain or service account, since those hashes are the most valuable to an attacker. Exploitation has not yet been confirmed (not in CISA KEV, no public PoC), but EPSS assigns a 35.2% probability of exploitation within 30 days (98th percentile), making this a high-priority patch. Do: Upgrade DNN Platform to version 10.0.1 or later as soon as possible. As interim mitigation, restrict outbound SMB (TCP 445) from web servers to trusted destinations only and run the application pool under a low-privilege, non-domain account so leaked hashes have limited value; monitor for unexpected SMB connections to external hosts. Given the high EPSS score, prioritize patching of internet-exposed DNN instances. | 8.6 group max | 35% |
| largetens of thousands of internet-facing DNN sites (of an installed base of roughly 100k+ live DNN sites) | ||
| CVE-2025-48378 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue. NVD description · AI analysis pending | 6.1 group max | <1% |
| — | ||
| CVE-2025-32374 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2025-32035 +1 in the same advisory: …32036 | DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 9.13.2, when uploading files (e.g. when uploading assets), the file extension is checked to see if it's an allowed file type but the actual contents of the file aren't checked. This means that it's possible to e.g. upload an executable file renamed to be a .jpg. This file could then be executed by another security vulnerability. This vulnerability is fixed in 9.13.2. NVD description · AI analysis pending | 7.5 group max | <1% |
| — | ||
| CVE-2022-47053 | An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2022-2922 | Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0. Relative Path Traversal in GitHub repository dnnsoftware/dnn.platform prior to 9.11.0. NVD description · AI analysis pending | 4.9 | 1% | PoC |
| — | |
| CVE-2021-31858 | DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2021-40186 | The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common scenario, the attacker exploits SSRF vulnerabilities to attack systems behind the firewall and access sensitive information from Cloud Provider metadata services. NVD description · AI analysis pending | 7.5 | 1% | PoC |
| — | |
| CVE-2020-11585 | There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter. NVD description · AI analysis pending | 4.3 | <1% | PoC |
| — | |
| CVE-2020-5187 | DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2). NVD description · AI analysis pending | 8.8 group max | 2% | PoC |
| — | |
| CVE-2019-12562 | Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting. NVD description · AI analysis pending | 6.1 | 6% | PoC |
| — | |
| CVE-2018-18326 +1 in the same advisory: …15812 | DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812. NVD description · AI analysis pending | 7.5 | 54% | PoC |
| — | |
| CVE-2018-18325 +1 in the same advisory: …15811 | Unauthenticated deserialization RCE via weak encryption in DotNetNuke 9.2-9.2.2 DNN (DotNetNuke) 9.2 through 9.2.2 protects input parameters, including the cookie values used for authentication state, with an encryption algorithm that is too weak; this flaw exists because the earlier fix for CVE-2018-15811 was incomplete. A remote, unauthenticated attacker can abuse the inadequate cryptography to forge or tamper with encrypted parameter values, which the application then deserializes, bypassing the original patch. Successful exploitation exposes sensitive information and, as demonstrated by the public cookie-deserialization exploit, can lead to full remote code execution on the web server. Any organization running DNN 9.2 through 9.2.2, typically as a public-facing .NET CMS website, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 and carries a 74% EPSS probability of exploitation in the next 30 days (99th percentile). Do: Upgrade DNN to the updated 9.2.2 release that completes the CVE-2018-15811 fix, or to a later supported version, following vendor update instructions; this is a CISA KEV item, so patching is urgent. Verify the exact version deployed, since sites on the original 9.2.2 build may still lack the complete fix, and until patched, restrict internet exposure of the site and monitor for exploitation of the cookie deserialization path. | 7.5 | 74% | KEV PoC |
| largetens of thousands of internet-exposed DNN sites | |
| CVE-2018-14486 | DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. NVD description · AI analysis pending | 6.1 | 1% | PoC |
| — | |
| CVE-2017-0929 | DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources. NVD description · AI analysis pending | 7.5 | 13% |
| — | ||
| CVE-2017-9822 | Cookie Deserialization RCE in DotNetNuke (DNN) before 9.1.1 CVE-2017-9822 is a remote code execution flaw (CWE-94, code injection) in DotNetNuke (DNN) before 9.1.1, caused by insecure handling of a cookie, which the vendor flagged as a critical 2017-08 security issue. An attacker triggers the flaw by sending a maliciously crafted cookie to an affected DNN site; the CVSS vector (AV:N/PR:L/UI:N) indicates network-based exploitation with low-privileged access required and no user interaction. Successful exploitation yields full high-impact compromise (C:H/I:H/A:H), meaning arbitrary code execution and the ability to read, alter, or destroy data on the web server, a suitable foothold for follow-on actions such as ransomware or cryptojacking. Any DNN (formerly DotNetNuke) deployment running a version prior to 9.1.1 is affected, which includes a broad base of CMS sites built on the vendor's platform. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, ransomware use noted), it carries a very high EPSS score of 94.8%, and a public proof of concept exists, with related server compromise campaigns such as the Zealot campaign illustrating how unpatched web servers are targeted for Monero coin-mining payloads. Do: Apply updates per vendor instructions by upgrading DNN/DotNetNuke to version 9.1.1 or later, prioritizing internet-facing DNN sites given the CISA KEV listing and known ransomware use. In the interim, review web server logs for suspicious or oversized cookie values being processed by DNN endpoints, and consider WAF rules to limit or inspect serialized payloads in cookies. Inventory all DNN portals in your environment and confirm their version, since older legacy deployments are the primary risk. | 8.8 | 95% | KEV ransomware PoC |
| large≈100,000–750,000 deployments (vendor historically claimed 750,000+ DNN sites; internet-exposed count from scans not provided) | |
| CVE-2016-7119 | Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbi Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element. NVD description · AI analysis pending | 5.4 | <1% |
| — |