VendorsDNN Softwaredotnetnukeall versions
Vulnerabilities

DNN Software DotNetNuke

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

76CVEs
CVE-2025-52486
DNN.PLATFORM Allows Reflected Cross-Site Scripting (XSS) in some TokenReplace situations with SkinObjects
Published 2025-06-21 · Analyzed
6.1EPSS 0.002
CVE-2025-59548
DNN Vulnerable to Reflected Cross-Site Scripting (XSS) in CKEditor File Browser
Published 2025-09-23 · Analyzed
6.1EPSS 0.002
CVE-2025-48377
Dnn.Platform vulnerable to Reflected Cross-Site Scripting (XSS) in module actions in edit mode
Published 2025-05-23 · Analyzed
6.0EPSS 0.002
CVE-2020-5186
DNN (formerly DotNetNuke) through 9.4.4 allows XSS (issue 1 of 2).
Published 2020-02-24 · Modified
5.4EPSS 0.009
CVE-2016-7119
Cross-site scripting (XSS) vulnerability in the user-profile biography section in DotNetNuke (DNN) before 8.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted onclick attribute in an IMG element.
Published 2016-08-31 · Modified
5.4EPSS 0.007
CVE-2021-31858
DotNetNuke (DNN) 9.9.1 CMS is vulnerable to a Stored Cross-Site Scripting vulnerability in the user profile biography section which allows remote authenticated users to inject arbitrary code via a crafted payload.
Published 2022-07-20 · Modified
5.4EPSS 0.006
CVE-2022-47053
An arbitrary file upload vulnerability in the Digital Assets Manager module of DNN Corp DotNetNuke v7.0.0 to v9.10.2 allows attackers to execute arbitrary code via a crafted SVG file.
Published 2023-04-12 · Modified
5.4EPSS 0.004
CVE-2025-52485
DNN.PLATFORM Allows Stored Cross-Site Scripting (XSS) in Activity Feed
Published 2025-06-21 · Analyzed
5.4EPSS 0.002
CVE-2025-59547
DNN's CKEditor File Uploader functionality vulnerable through Unicode obfuscation
Published 2025-09-23 · Analyzed
5.3EPSS 0.003
CVE-2008-6540
DotNetNuke before 4.8.2, during installation or upgrade, does not warn the administrator when the default (1) ValidationKey and (2) DecryptionKey values cannot be modified in the web.config file, which allows remote attackers to bypass intended access restrictions by using the default keys.
Published 2009-03-30 · Modified
5.11 PoCEPSS 0.025
CVE-2004-2323
DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to obtain sensitive information, including the SQL server username and password, via a GET request for source or configuration files such as Web.config.
Published 2005-08-16 · Modified
5.0EPSS 0.014
CVE-2008-7101
Unspecified vulnerability in DotNetNuke 4.0 through 4.8.4 and 5.0 allows remote attackers to obtain sensitive information (portal number) by accessing the install wizard page via unknown vectors.
Published 2009-08-27 · Modified
5.0EPSS 0.013
CVE-2009-4109
The install wizard in DotNetNuke 4.0 through 5.1.4 does not prevent anonymous users from accessing functionality related to determination of the need for an upgrade, which allows remote attackers to access version information and possibly other sensitive information.
Published 2009-11-28 · Modified
5.0EPSS 0.012
CVE-2022-2922
Relative Path Traversal in dnnsoftware/dnn.platform
Published 2022-09-30 · Modified
4.9EPSS 0.011
CVE-2025-59546
DNN Vulnerable to Stored XSS Using Backend Admin Credentials
Published 2025-09-23 · Analyzed
4.8EPSS 0.002
CVE-2008-6542
Unspecified vulnerability in the Skin Manager in DotNetNuke before 4.8.2 allows remote authenticated administrators to perform "server-side execution of application logic" by uploading a static file that is converted into a dynamic script via unknown vectors related to HTM or HTML files.
Published 2009-03-30 · Modified
4.6EPSS 0.016
CVE-2013-4649
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI.
Published 2014-03-12 · Modified
4.3EPSS 0.025
CVE-2006-4973
Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.
Published 2006-09-25 · Modified
4.31 PoCEPSS 0.019
CVE-2015-1566
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 7.4.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published 2015-02-09 · Modified
4.3EPSS 0.018
CVE-2009-4110
Cross-site scripting (XSS) vulnerability in the search functionality in DotNetNuke 4.8 through 5.1.4 allows remote attackers to inject arbitrary web script or HTML via search terms that are not properly filtered before display in a custom results page.
Published 2009-11-28 · Modified
4.3EPSS 0.017
CVE-2010-4514
Cross-site scripting (XSS) vulnerability in Install/InstallWizard.aspx in DotNetNuke 5.05.01 and 5.06.00 allows remote attackers to inject arbitrary web script or HTML via the __VIEWSTATE parameter. NOTE: some of these details are obtained from third party information.
Published 2010-12-09 · Modified
4.31 PoCEPSS 0.015
CVE-2008-6644
Cross-site scripting (XSS) vulnerability in Default.aspx in DotNetNuke 4.8.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
Published 2009-04-07 · Modified
4.31 PoCEPSS 0.015
CVE-2005-0040
Multiple cross-site scripting (XSS) vulnerabilities in DotNetNuke before 3.0.12 allow remote attackers to inject arbitrary web script or HTML via the (1) register a new user page, (2) User-Agent, or (3) Username, which is not properly quoted before sending to the error log.
Published 2005-05-19 · Modified
4.3EPSS 0.013
CVE-2004-2325
Cross-site scripting (XSS) vulnerability in EditModule.aspx for DotNetNuke (formerly IBuySpy Workshop) 1.0.6 through 1.0.10d allows remote attackers to inject arbitrary web script or HTML.
Published 2005-08-16 · Modified
4.3EPSS 0.012
CVE-2013-7335
Open redirect vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published 2014-03-12 · Modified
4.3EPSS 0.012
CVE-2008-6732
Cross-site scripting (XSS) vulnerability in the Language skin object in DotNetNuke before 4.8.4 allows remote attackers to inject arbitrary web script or HTML via "newly generated paths."
Published 2009-04-21 · Modified
4.3EPSS 0.011
CVE-2008-6733
Cross-site scripting (XSS) vulnerability in the error handling page in DotNetNuke 4.6.2 through 4.8.3 allows remote attackers to inject arbitrary web script or HTML via the querystring parameter.
Published 2009-04-21 · Modified
4.3EPSS 0.011
CVE-2009-1366
Cross-site scripting (XSS) vulnerability in Website\admin\Sales\paypalipn.aspx in DotNetNuke (DNN) before 4.9.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to "name/value pairs" and "paypal IPN functionality."
Published 2009-04-22 · Modified
4.3EPSS 0.010
CVE-2012-1036
Cross-site scripting (XSS) vulnerability in the telerik HTML editor in DotNetNuke before 5.6.4 and 6.x before 6.1.0 allows remote attackers to inject arbitrary web script or HTML via a message.
Published 2012-04-11 · Modified
4.3EPSS 0.009
CVE-2012-1030
Cross-site scripting (XSS) vulnerability in DotNetNuke 6.x through 6.0.2 allows user-assisted remote attackers to inject arbitrary web script or HTML via a crafted URL containing text that is used within a modal popup.
Published 2012-04-11 · Modified
4.3EPSS 0.009
CVE-2020-11585
There is an information disclosure issue in DNN (formerly DotNetNuke) 9.5 within the built-in Activity-Feed/Messaging/Userid/ Message Center module. A registered user is able to enumerate any file in the Admin File Manager (other than ones contained in a secure folder) by sending themselves a message with the file attached, e.g., by using an arbitrary small integer value in the fileIds parameter.
Published 2020-04-06 · Modified
4.3EPSS 0.007
CVE-2025-32371
Unexpected external content may be displayed in DNN ImageHandler
Published 2025-04-09 · Analyzed
4.3EPSS 0.003
CVE-2025-62802
DNN CKEditor Provider allows unauthenticated upload out-of-the-box
Published 2025-10-28 · Analyzed
4.3EPSS 0.002
CVE-2026-40305
DNN has Force Friend Request Acceptance
Published 2026-04-17 · Analyzed
4.3EPSS 0.002
CVE-2013-3943
Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote authenticated users to inject arbitrary web script or HTML via vectors related to the Display Name field in the Manage Profile.
Published 2014-03-12 · Modified
3.5EPSS 0.009
CVE-2025-48376
Dnn.Platform's Site Import could use an external source with a crafted request
Published 2025-05-23 · Analyzed
3.5EPSS 0.002
← Prev2 / 2