DotNetNuke.Web
DNN (formerly DotNetNuke) is the leading open source web content management platform (CMS) in the Microsoft ecosystem.
Activity
- Latest release
- 1mo ago
- Total releases
- 77
- Cadence
- ~39 days
- Last 12 months
- 15
Reach
- Stars
- 1.1k
Details
- License
- MIT
- First release
- Jun 13, 2013
| Version | Released | |
|---|---|---|
10.3.3
patch
| ||
10.3.3-rc.1
pre
| ||
10.3.2
patch
| ||
10.3.2-rc.1
pre
| ||
10.3.1
patch
| ||
10.3.1-rc.1
pre
| ||
10.3.0
minor
| ||
10.3.0-rc.2
pre
| ||
10.2.4-bulk-install-packaging.1+335
pre
| ||
10.2.4-bulk-install.1+329
pre
| ||
10.2.3
patch
| ||
10.2.2
patch
| ||
10.2.1
patch
| ||
10.2.0
minor
| ||
10.1.2
patch
| ||
10.1.1
patch
| ||
10.1.0
minor
| ||
10.0.1
patch
| ||
9.13.9
patch
| ||
10.0.0
major
| ||
10.0.0-rc.2
pre
| ||
9.13.8
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.7
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.6
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.5
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.5-ci0062
pre
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.4
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.3
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.2
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.1
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.13.0
minor
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.12.0
minor
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.11.2
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.11.1
patch
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.11.0
minor
1 CVE
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev | ||
9.10.2
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.10.1
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.10.0
minor
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.9.1
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.9.0
minor
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.7.2
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.8.0
minor
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.7.1
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.7.0
minor
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.6.2
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.6.1
minor
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.5.0
minor
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.4.4
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.4.3
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev | ||
9.4.2
patch
2 CVEs
CVE-2025-48377
GHSA-79m3-rvx2-3qq9
May 23, 2025
Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Medium
Network
Low
Low
A specially crafted URL may be constructed which can inject an XSS payload that is triggered by using some module actions. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 45 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.11.0
9.11.1
9.11.2
9.12.0
9.13.0
9.13.0-ci0000
9.13.1
9.13.2
9.13.3
9.13.4
9.13.5
9.13.5-ci0062
9.13.6
9.13.7
9.13.8
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.13.9
References Updated May 23, 2025 · Source: OSV.dev
CVE-2022-2922
GHSA-9w72-2f23-57gm
Oct 01, 2022
DNN vulnerable to Relative Path Traversal
4.9
/ 10
Medium
Network
Low
High
None
Unchanged
High
None
None
DNN (GitHub repository dnnsoftware/dnn.platform) prior to 9.11.0 is vulnerable to Relative Path Traversal. Version 9.11.0 contains a patch for this issue. Affected versions
6.0.0
7.0.0
7.0.6.121
7.1.0
7.1.2
7.2.0.613
7.3.0.499
7.3.1.20
7.4.0.353
7.4.1.280
7.4.2.216
8.0.0.809
+ 30 more Show less
8.0.1.239
8.0.2.4
8.0.3.5
8.0.4.226
9.0.0.1002
9.0.1.142
9.1.0.367
9.1.1.129
9.10.0
9.10.1
9.10.2
9.2.0.366
9.2.1.533
9.3.0
9.3.1
9.3.2
9.4.0
9.4.1
9.4.2
9.4.3
9.4.4
9.5.0
9.6.1
9.6.2
9.7.0
9.7.1
9.7.2
9.8.0
9.9.0
9.9.1
Fixed in
9.11.0
References
Updated Nov 08, 2023 · Source: OSV.dev |