VendorsDNN Softwaredotnetnukeany version
Vulnerabilities

DNN Software DotNetNuke any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

61CVEs
CVE-2025-64095
DNN Insufficient Access Control - Image Upload allows for Site Content Overwrite
Published 2025-10-28 · Analyzed
10.0EPSS 0.447
CVE-2006-3601
** UNVERIFIABLE ** Unspecified vulnerability in an unspecified DNN Modules module for DotNetNuke (.net nuke) allows remote attackers to gain privileges via unspecified vectors, as used in an attack against the Microsoft France web site. NOTE: due to the lack of details and uncertainty about which product is affected, this claim is not independently verifiable.
Published 2006-07-14 · Modified
10.0EPSS 0.025
CVE-2015-2794
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain SuperUser access via a direct request to Install/InstallWizard.aspx.
Published 2017-02-06 · Modified
9.81 PoCEPSS 0.751
CVE-2026-24838
DotNetNuke.Core Vulnerable to Stored XSS via Module Title
Published 2026-01-27 · Analyzed
9.1EPSS 0.002
CVE-2025-59545
DNN Vulnerable to Stored Cross-Site Scripting (XSS) in the Prompt module
Published 2025-09-23 · Analyzed
9.0EPSS 0.005
CVE-2017-9822
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
Published 2017-07-20 · Analyzed
8.8KEV1 PoCEPSS 0.948
CVE-2020-5187
DNN (formerly DotNetNuke) through 9.4.4 allows Path Traversal (issue 2 of 2).
Published 2020-02-24 · Modified
8.8EPSS 0.024
CVE-2025-52487
DNN.PLATFORM possibly allows bypass of IP Filters
Published 2025-06-21 · Analyzed
8.8EPSS 0.003
CVE-2025-52488
DNN.PLATFORM leaks NTLM hash via SMB Share Interaction with malicious user input
Published 2025-06-21 · Analyzed
8.6EPSS 0.358
CVE-2026-40321
DotNetNuke.Core has stored cross-site-scripting (XSS) via SVG upload
Published 2026-04-17 · Analyzed
8.0EPSS 0.004
CVE-2026-24837
DotNetNuke.Core Vulnerable to Stored XSS in Module Deletion Confirmation Modal
Published 2026-01-27 · Analyzed
7.6EPSS 0.003
CVE-2026-24836
DotNetNuke.Core Vulnerable to Stored XSS in Scheduler LogNotes
Published 2026-01-27 · Analyzed
7.6EPSS 0.003
CVE-2026-24833
DotNetNuke.Core Vulnerable to Stored XSS in Module Description
Published 2026-01-27 · Analyzed
7.6EPSS 0.002
CVE-2018-15811
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
Published 2019-07-03 · Analyzed
7.5KEV1 PoCEPSS 0.763
CVE-2018-18325
DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.
Published 2019-07-03 · Analyzed
7.5KEV1 PoCEPSS 0.740
CVE-2018-18326
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.
Published 2019-07-03 · Modified
7.51 PoCEPSS 0.545
CVE-2018-15812
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
Published 2019-07-03 · Modified
7.51 PoCEPSS 0.475
CVE-2017-0929
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
Published 2018-07-03 · Modified
7.5EPSS 0.125
CVE-2021-40186
DNN CMS Server-Side Request Forgery (SSRF)
Published 2022-05-31 · Modified
7.5EPSS 0.011
CVE-2025-32374
Possible Denial of Service (DoS) in DNN.PLATFORM registration
Published 2025-04-09 · Analyzed
7.5EPSS 0.004
CVE-2025-32372
Server-Side Request Forgery (SSRF) in DotNetNuke.Core
Published 2025-04-09 · Analyzed
7.5EPSS 0.004
CVE-2025-32035
DNN does not check the contents of a file when uploading files
Published 2025-04-08 · Analyzed
7.5EPSS 0.002
CVE-2026-40306
DNN has same HostGUID for all new installs
Published 2026-04-17 · Analyzed
6.9EPSS 0.003
CVE-2008-6541
Unrestricted file upload vulnerability in the file manager module in DotNetNuke before 4.8.2 allows remote administrators to upload arbitrary files and gain privileges to the server via unspecified vectors.
Published 2009-03-30 · Modified
6.8EPSS 0.010
CVE-2026-24784
DotNetNuke.Core has a potential XSS vulnerability in modules' header and footer
Published 2026-01-27 · Analyzed
6.8EPSS 0.002
CVE-2020-5188
DNN (formerly DotNetNuke) through 9.4.4 has Insecure Permissions.
Published 2020-02-24 · Modified
6.5EPSS 0.018
CVE-2025-32373
DNN allows a registered user to enumerate and access files they should not have access to
Published 2025-04-09 · Analyzed
6.5EPSS 0.004
CVE-2025-59535
DotNetNuke.Core allows loading of unused themes on anonymous clients through query parameters
Published 2025-09-22 · Analyzed
6.5EPSS 0.003
CVE-2025-32036
DNN allows the possibility of bypassing Captcha
Published 2025-04-08 · Analyzed
6.5EPSS 0.003
CVE-2025-59821
DNN vulnerable to Reflected Cross-Site Scripting (XSS) using url to profile
Published 2025-09-23 · Analyzed
6.5EPSS 0.002
CVE-2020-37103
DotNetNuke 9.5 - Persistent Cross-Site Scripting
Published 2026-02-03 · Analyzed
6.4EPSS 0.003
CVE-2025-64094
DNN vulnerable to stored cross-site-scripting (XSS) via SVG upload
Published 2025-10-28 · Analyzed
6.4EPSS 0.002
CVE-2025-59539
DNN affected by Stored Cross-Site Scripting (XSS) in Profile Biography field
Published 2025-09-23 · Analyzed
6.3EPSS 0.002
CVE-2019-12562
Stored Cross-Site Scripting in DotNetNuke (DNN) Version before 9.4.0 allows remote attackers to store and embed the malicious script into the admin notification page. The exploit could be used to perfom any action with admin privileges such as managing content, adding users, uploading backdoors to the server, etc. Successful exploitation occurs when an admin user visits a notification page with stored cross-site scripting.
Published 2019-09-26 · Modified
6.11 PoCEPSS 0.062
CVE-2025-48378
Dnn.Platform vulnerable to Stored Cross-Site Scripting (XSS) with svg files rendered inline
Published 2025-05-23 · Analyzed
6.1EPSS 0.003
CVE-2025-52486
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Published 2025-06-21 · Analyzed
6.1EPSS 0.002
CVE-2025-59548
DNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browser
Published 2025-09-23 · Analyzed
6.1EPSS 0.002
CVE-2025-48377
Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Published 2025-05-23 · Analyzed
6.0EPSS 0.002
CVE-2020-5186
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
Published 2020-02-24 · Modified
5.4EPSS 0.009
CVE-2016-7119
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
Published 2016-08-31 · Modified
5.4EPSS 0.007
1 / 2Next →