DotNetNuke.Core
DNN (formerly DotNetNuke) is the leading open source web content management platform (CMS) in the Microsoft ecosystem.
Activity
- Latest release
- 1mo ago
- Total releases
- 78
- Cadence
- ~39 days
- Last 12 months
- 15
Reach
- Stars
- 1.1k
Details
- License
- MIT
- First release
- Jun 13, 2013
| Version | Released | |
|---|---|---|
10.3.3
patch
| ||
10.3.3-rc.1
pre
| ||
10.3.2
patch
| ||
10.3.2-rc.1
pre
| ||
10.3.1
patch
| ||
10.3.1-rc.1
pre
| ||
10.3.0
minor
| ||
10.3.0-rc.2
pre
| ||
10.2.4-bulk-install-packaging.1+335
pre
| ||
10.2.4-bulk-install.1+329
pre
| ||
10.2.3
patch
| ||
10.2.2
patch
| ||
10.2.1
patch
4 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev | ||
10.2.0
minor
4 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev | ||
10.1.2
patch
8 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev | ||
10.1.1
patch
8 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev | ||
10.1.0
minor
9 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev | ||
10.0.1
patch
14 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev | ||
9.13.9
patch
13 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev | ||
10.0.0
major
14 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40306
GHSA-2rhw-gw3f-477j
Apr 10, 2026
DNN: Same HostGUID for all new installs
Medium
Network
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev | ||
10.0.0-rc.2
pre
9 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev | ||
9.13.8
patch
15 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.7
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.7-ci0064
pre
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.6
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.5
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.5-ci0062
pre
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.4
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.3
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.2
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.1
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.13.0
minor
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.12.0
minor
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.11.2
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.11.1
patch
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.11.0
minor
16 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev | ||
9.10.2
patch
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.10.1
patch
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.10.0
minor
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.9.1
patch
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.9.0
minor
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.7.2
patch
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.8.0
minor
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.7.1
patch
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.7.0
minor
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.6.2
patch
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.6.1
minor
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.5.0
minor
17 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.4.4
patch
20 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5188
GHSA-vjcm-j85r-7p68
May 24, 2022
DNN File Upload Vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
DNN (formerly DotNetNuke) through 9.4.4 has a File upload vulnerability via bypassing client-side file extension check Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 18 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-5187
GHSA-4qf5-7xc2-wqpg
May 24, 2022
DNN Path Traversal via Zip Slip
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal via unsafe handling of zip files Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 18 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
Fixed in
9.5.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-5186
GHSA-9phr-h5mx-4fp6
May 24, 2022
DNN XSS Vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 18 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
References Updated Feb 16, 2024 · Source: OSV.dev | ||
9.4.3
patch
20 CVEs
GHSA-fcpv-w245-r2q7
Apr 14, 2026
DotNetNuke.Core security code analysis rules triggered
Low
The codebase raises code analysis warnings related to security, including CA3075, CA5366, CA5371, CA5368, CA5369, CA5372, CA5379, CA5350, and CA5351. Most of these deal with disabling DTD processing in XML documents, but also includes cryptographic algorithm choices. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated Apr 14, 2026 · Source: OSV.dev
CVE-2026-40305
GHSA-fpj4-9qhx-5m6m
Apr 10, 2026
DNN: Force Friend Request Acceptance
4.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
None
None
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 6.0.0 and prior to version 10.2.2, in the friends feature, a user could craft a request that would force the acceptance of a friend request on another user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-40321
GHSA-ffq7-898w-9jc4
Apr 10, 2026
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
8.0
/ 10
High
Network
High
Low
Required
Changed
High
High
High
DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.2.2, a user could upload a specially crafted SVG file that could include scripts that can target both authenticated and unauthenticated DNN users. The impact is increased if the scripts are run by a power user. Version 10.2.2 patches the issue. Affected versions
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
10.2.0
10.2.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
+ 54 more Show less
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.2.2
References Updated May 05, 2026 · Source: OSV.dev
CVE-2026-24838
GHSA-w9pf-h6m6-v89h
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
9.1
/ 10
Critical
Network
Low
High
None
Changed
High
High
High
Module title supports richtext which could include scripts that would execute in certain scenarios. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 52 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References
Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24837
GHSA-vm5q-8qww-h238
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
A module friendly name could include scripts that will run during some module operations in the Persona Bar. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.2.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24836
GHSA-2g5g-hcgh-q3rp
Jan 28, 2026
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
7.6
/ 10
High
Network
High
High
Required
Changed
High
High
High
Extensions could write richtext in log notes which can include scripts that would run in the PersonaBar when displayed. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
10.02.0
References Updated Feb 03, 2026 · Source: OSV.dev
CVE-2026-24784
GHSA-jjwg-4948-6wxp
Jan 28, 2026
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
6.9
/ 10
Medium
Network
Low
High
Required
Changed
High
Low
None
A content editor could inject scripts in module headers/footers that would run for other users. Affected versions
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
+ 36 more Show less
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
10.0.0
10.0.1
10.1.0
10.1.1
10.1.2
Fixed in
9.13.10
10.2.0
References Updated Feb 04, 2026 · Source: OSV.dev
CVE-2025-64094
GHSA-hmvq-8p83-cq52
Oct 29, 2025
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
6.4
/ 10
Medium
Network
Low
Low
None
Changed
Low
Low
None
SummarySanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. DetailsDNN validates the contents of SVG's to ensure they are valid and do not contain any malicious code. These checks were introduced as part of However, the checks to ensure there are no script elements within the SVG files are not comprehensive and may allow some malicious SVG files to be uploaded. As this vulnerability allows for the execution of arbitrary JavaScript code within the context of the user's browser, it can lead to a range of attacks, including data exfiltration, session hijacking, and defacement of the web application to name a few. Affected versions
10.0.0
10.0.1
10.1.0
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
+ 50 more Show less
7.4.1.280
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.1
References Updated Oct 29, 2025 · Source: OSV.dev
CVE-2025-59821
GHSA-jc4g-c8ww-5738
Sep 23, 2025
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
High
None
None
SummaryA reflected cross-site scripting (XSS) vulnerability exists under certain conditions, using a specially crafter url to view a user profile DescriptionDNN’s URL/path handling and template rendering can allow specially crafted input to be reflected into a user profile that are returned to the browser. In these cases, the application does not sufficiently neutralize or encode characters that are meaningful in HTML, so an attacker can cause a victim’s browser to interpret attacker-controlled content as part of the page’s HTML. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59546
GHSA-gj8m-5492-q98h
Sep 23, 2025
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
2.4
/ 10
Low
Network
Low
High
Required
Unchanged
None
Low
None
SummaryUsers that can edit modules could set a title that includes scripts. DescriptionSome users (administrators and content editors) can set html in module titles and that could include javascript which could be used for XSS based attacks. With the addition of more roles being able to set module titles, this is not strictly limited to administrators. However since HTML in module titles could be a valid use case, we have added a setting for this functionality in the Security module in the Persona Bar. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59545
GHSA-2qxc-mf4x-wr29
Sep 23, 2025
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
9.0
/ 10
Critical
Network
Low
Low
Required
Changed
High
High
High
SummaryThe Prompt module allows execution of commands that can return raw HTML. Malicious input, even if sanitized for display elsewhere, can be executed when processed through certain commands, leading to potential script execution (XSS). DescriptionThe application sanitizes most user-submitted data before displaying it in entry forms. However, the Prompt module is capable of running commands whose output is treated as HTML. This creates a vulnerability where a malicious user can craft input containing embedded scripts or harmful markup. If such malicious content is later processed by a Prompt command and returned as HTML, it bypasses the standard sanitation mechanisms. Simply executing a specific command through the Prompt module could render this untrusted data and cause unintended script execution in the browser specially in the context of a super-user. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59539
GHSA-7rcc-q6rq-jpcm
Sep 22, 2025
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
6.3
/ 10
Medium
Network
Low
Low
None
Unchanged
Low
Low
Low
SummaryUsers can use special syntax to inject javascript code in their profile biography field. Although there was sanitization in place, it did not cover all possible scenarios DescriptionWhen embedding information in the Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References Updated Sep 23, 2025 · Source: OSV.dev
CVE-2025-59535
GHSA-wq2j-w9pm-7x2p
Sep 22, 2025
DNN allows loading unused themes on anonymous clients through query parameters
6.5
/ 10
Medium
Network
Low
None
None
Unchanged
None
Low
Low
SummaryArbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this could be loaded on unsuspecting clients without knowledge of the site owner. DetailsMany people who run DNN sites have a number of installed themes that they do not actually use. This could be because they were testing many themes during initial setup, because they have changed themes over time, or because they have development and production versions of a theme. Whatever the reason, many times the unused themes will become outdated over time as site admins wouldn't have reason to update something that is not used. However, this could introduce an entry point to exploit a vulnerable theme by making the server run the unused theme for unsuspecting client requests. Depending on the vulnerability in a theme, this could lead to server side or client side arbitrary code execution. With DNN 10.1.0 this functionality is now disabled by default but a setting was introduced in the Security module to turn activate the functionality. Affected versions
10.0.0
10.0.1
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
+ 49 more Show less
7.4.2.216
8.0.0.809
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.13.9
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
10.1.0
References
Updated Sep 22, 2025 · Source: OSV.dev
CVE-2025-48378
GHSA-m4hf-fxcg-cp34
May 23, 2025
DNN allows Stored Cross-Site Scripting (XSS) with svg files rendered inline
Medium
Network
Low
Low
Uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 46 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2025-32372
GHSA-3f7v-qx94-666m
Apr 09, 2025
DotNetNuke.Core Vulnerable to Server-Side Request Forgery (SSRF)
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
High
None
A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target systems, including internal or adjacent networks. ImpactThis vulnerability facilitates a semi-blind SSRF attack, allowing attackers to make the target server send requests to internal or external URLs without viewing the full responses. Potential impacts include internal network reconnaissance, bypassing firewalls. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.7-ci0064
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.8
References Updated Apr 09, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev
CVE-2020-5188
GHSA-vjcm-j85r-7p68
May 24, 2022
DNN File Upload Vulnerability
6.5
/ 10
Medium
Network
Low
Low
None
Unchanged
None
High
None
DNN (formerly DotNetNuke) through 9.4.4 has a File upload vulnerability via bypassing client-side file extension check Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 18 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
References
Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-5187
GHSA-4qf5-7xc2-wqpg
May 24, 2022
DNN Path Traversal via Zip Slip
8.8
/ 10
High
Network
Low
Low
None
Unchanged
High
High
High
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal via unsafe handling of zip files Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 18 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
Fixed in
9.5.0
References Updated Feb 16, 2024 · Source: OSV.dev
CVE-2020-5186
GHSA-9phr-h5mx-4fp6
May 24, 2022
DNN XSS Vulnerability
5.4
/ 10
Medium
Network
Low
Low
Required
Changed
Low
Low
None
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2). Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 18 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
References Updated Feb 16, 2024 · Source: OSV.dev |