VYPR

Dotnetnuke

by Dnnsoftware

Source repositories

CVEs (76)

  • CVE-2025-32373MedApr 9, 2025
    risk 0.42cvss 6.5epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In limited configurations, registered users may be able to craft a request to enumerate/access some portal files they should not have access to. This vulnerability is…

  • CVE-2021-40186MedJun 2, 2022
    risk 0.42cvss 6.5epss 0.01

    The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of…

  • CVE-2020-5188MedFeb 24, 2020
    risk 0.42cvss 6.5epss 0.02

    DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.

  • CVE-2025-59539MedSep 23, 2025
    risk 0.41cvss 6.3epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, when embedding information in the Biography field, even if that field is not rich-text, users could inject javascript code that would run in the…

  • CVE-2025-59548MedSep 23, 2025
    risk 0.40cvss 6.1epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, specially crafted URLs to the FileBrowser are vulnerable to javascript injection, affecting any unsuspecting user clicking such link. This issue…

  • CVE-2018-14486MedMar 21, 2019
    risk 0.40cvss 6.1epss 0.01

    DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.

  • CVE-2025-32374MedApr 9, 2025
    risk 0.38cvss 5.9epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Possible denial of service with specially crafted information in the public registration form. This vulnerability is fixed in 9.13.8.

  • CVE-2026-24784MedJan 28, 2026
    risk 0.37cvss 6.8epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Starting in version 9.0.0 and prior to versions 9.13.10 and 10.2.0, a content editor could inject scripts in module headers/footers that would run for other users.…

  • CVE-2026-40306MedApr 17, 2026
    risk 0.35cvss 6.5epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. All new installations of DNN 10.x.x - 10.2.1 have the same Host GUID. This does not affect upgrades from 9.x.x. Version 10.2.2 patches the issue.

  • CVE-2025-64094MedOct 28, 2025
    risk 0.35cvss 6.4epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to 10.1.1, sanitization of the content of uploaded SVG files was not covering all possible XSS scenarios. This vulnerability exists because of an incomplete fix…

  • CVE-2025-59535MedSep 22, 2025
    risk 0.35cvss 6.5epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, arbitrary themes can be loaded through query parameters. If an installed theme had a vulnerability, even if it was not used on any page, this…

  • CVE-2025-52485MedJun 21, 2025
    risk 0.35cvss 5.4epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows a specially crafted request to inject scripts in the Activity Feed Attachments endpoint which will then render in…

  • CVE-2025-32372MedApr 9, 2025
    risk 0.35cvss 6.5epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. A bypass has been identified for the previously known vulnerability CVE-2017-0929, allowing unauthenticated attackers to execute arbitrary GET requests against target…

  • CVE-2022-47053MedApr 12, 2023
    risk 0.35cvss 5.4epss 0.00

    An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.

  • CVE-2021-31858MedJul 20, 2022
    risk 0.35cvss 5.4epss 0.01

    DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.

  • CVE-2020-5186MedFeb 24, 2020
    risk 0.35cvss 5.4epss 0.01

    DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).

  • CVE-2016-7119MedAug 31, 2016
    risk 0.35cvss 5.4epss 0.01

    Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.

  • CVE-2025-59547MedSep 23, 2025
    risk 0.34cvss 5.3epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 10.1.0, the CKEditor file upload endpoint has insufficient sanitization for filenames allowing probing network endpoints. A specially crafted request…

  • CVE-2025-52486MedJun 21, 2025
    risk 0.33cvss 6.1epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. In versions 6.0.0 to before 10.0.1, DNN.PLATFORM allows specially crafted content in URLs to be used with TokenReplace and not be properly sanitized by some SkinObjects.…

  • CVE-2025-48378MedMay 23, 2025
    risk 0.28cvss 5.4epss 0.00

    DNN (formerly DotNetNuke) is an open-source web content management platform (CMS) in the Microsoft ecosystem. Prior to version 9.13.9, uploaded SVG files could contain scripts and if rendered inline those scripts could run allowing XSS attacks. Version 9.13.9 fixes the issue.