VendorsDNN Softwaredotnetnukeall versions
Vulnerabilities

DNN Software DotNetNuke

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2025-64095
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
Published 2025-10-28 · Analyzed
10.0EPSS 0.447
CVE-2006-3601
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack against the Microsoft France web site. NOTE: due to the lack of details and uncertainty about which product is affected, this claim is not independently verifiable.
Published 2006-07-14 · Modified
10.0EPSS 0.025
CVE-2015-2794
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
Published 2017-02-06 · Modified
9.81 PoCEPSS 0.751
CVE-2026-24838
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
Published 2026-01-27 · Analyzed
9.1EPSS 0.002
CVE-2025-59545
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
Published 2025-09-23 · Analyzed
9.0EPSS 0.005
CVE-2017-9822
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Published 2017-07-20 · Analyzed
8.8KEV1 PoCEPSS 0.948
CVE-2020-5187
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
Published 2020-02-24 · Modified
8.8EPSS 0.024
CVE-2025-52487
DNN.PLATFORM possibly allows bypass of IP Filters
Published 2025-06-21 · Analyzed
8.8EPSS 0.003
CVE-2025-52488
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
Published 2025-06-21 · Analyzed
8.6EPSS 0.358
CVE-2026-40321
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
Published 2026-04-17 · Analyzed
8.0EPSS 0.064
CVE-2026-24837
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
Published 2026-01-27 · Analyzed
7.6EPSS 0.003
CVE-2026-24836
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
Published 2026-01-27 · Analyzed
7.6EPSS 0.002
CVE-2026-24833
DotNetNuke.Core Vulnerable to Stored XSS in Module Description
Published 2026-01-27 · Analyzed
7.6EPSS 0.002
CVE-2018-15811
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Published 2019-07-03 · Analyzed
7.5KEV1 PoCEPSS 0.740
CVE-2018-18325
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
Published 2019-07-03 · Analyzed
7.5KEV1 PoCEPSS 0.740
CVE-2018-18326
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
Published 2019-07-03 · Modified
7.51 PoCEPSS 0.545
CVE-2018-15812
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
Published 2019-07-03 · Modified
7.51 PoCEPSS 0.475
CVE-2017-0929
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
Published 2018-07-03 · Modified
7.5EPSS 0.125
CVE-2008-7102
DotNetNuke 2.0 through 4.8.4 allows remote attackers to load .ascx files instead of skin files, and possibly access privileged functionality, via unknown vectors related to parameter validation.
Published 2009-08-27 · Modified
7.5EPSS 0.014
CVE-2004-2324
SQL injection vulnerability in DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to modify the backend database via the (1) table and (2) field parameters in LinkClick.aspx.
Published 2005-08-16 · Modified
7.5EPSS 0.012
CVE-2021-40186
DNN CMS Server-Side Request Forgery (SSRF)
Published 2022-05-31 · Modified
7.5EPSS 0.011
CVE-2025-32374
Possible Denial of Service (DoS) in DNN.PLATFORM registration
Published 2025-04-09 · Analyzed
7.5EPSS 0.004
CVE-2025-32372
Server-Side Request Forgery (SSRF) in DotNetNuke.Core
Published 2025-04-09 · Analyzed
7.5EPSS 0.004
CVE-2025-32035
DNN does not check the contents of a file when uploading files
Published 2025-04-08 · Analyzed
7.5EPSS 0.002
CVE-2026-40306
DNN has same HostGUID for all new installs
Published 2026-04-17 · Analyzed
6.9EPSS 0.002
CVE-2008-6541
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
Published 2009-03-30 · Modified
6.8EPSS 0.010
CVE-2026-24784
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
Published 2026-01-27 · Analyzed
6.8EPSS 0.002
CVE-2020-5188
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
Published 2020-02-24 · Modified
6.5EPSS 0.018
CVE-2008-7100
Unspecified vulnerability in DotNetNuke 4.4.1 through 4.8.4 allows remote authenticated users to bypass authentication and gain privileges via unknown vectors related to a "unique id" for user actions and improper validation of a "user identity."
Published 2009-08-27 · Modified
6.5EPSS 0.012
CVE-2025-32373
DNN allows a registered user to enumerate and access files they should not have access to
Published 2025-04-09 · Analyzed
6.5EPSS 0.004
CVE-2025-59535
DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters
Published 2025-09-22 · Analyzed
6.5EPSS 0.003
CVE-2025-32036
DNN allows the possibility of bypassing Captcha
Published 2025-04-08 · Analyzed
6.5EPSS 0.003
CVE-2025-59821
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
Published 2025-09-23 · Analyzed
6.5EPSS 0.002
CVE-2008-6399
Unspecified vulnerability in DotNetNuke 4.5.2 through 4.9 allows remote attackers to "add additional roles to their user account" via unknown attack vectors.
Published 2009-03-05 · Modified
6.4EPSS 0.019
CVE-2020-37103
DotNetNuke 9.5 - Persistent Cross-Site Scripting
Published 2026-02-03 · Analyzed
6.4EPSS 0.003
CVE-2025-64094
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
Published 2025-10-28 · Analyzed
6.4EPSS 0.002
CVE-2025-59539
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
Published 2025-09-23 · Analyzed
6.3EPSS 0.002
CVE-2019-12562
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
Published 2019-09-26 · Modified
6.11 PoCEPSS 0.062
CVE-2018-14486
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
Published 2019-03-17 · Modified
6.1EPSS 0.011
CVE-2025-48378
Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline
Published 2025-05-23 · Analyzed
6.1EPSS 0.003
1 / 2Next →